368,657open jobs
9,442companies
50,883added this week
Browse all
Location
Remote/Hybrid
Overview
Company
Impact
Profile match
Visionet is a premier technology solutions and business process management company delivering high-impact strategies, techniques, and technologies for a hyper-competitive, digitally disruptive market.

The SOC Analyst is responsible for continuous security monitoring, alert triage, incident investigation, and Incident Response (IR) activities across the organisation's environment. The role involves identifying, analysing, containing, eradicating, and recovering from cybersecurity incidents while ensuring proper execution of all Incident Response lifecycle processes.

The SOC Analyst will investigate alerts, incidents, and security incidents generated from SIEM platforms and ticketing systems, perform proactive threat hunting, improve detection visibility through SIEM fine-tuning and engineering, and coordinate remediation activities with internal stakeholders. The role also requires leading incident bridge calls, driving remediation efforts, and ensuring timely closure of security incidents in alignment with organisational security policies and SLAs.

Strong hands-on experience with Azure Cloud Security, including Microsoft Entra ID (Azure AD), Azure Defender for Cloud, Azure Security Centre, Conditional Access, RBAC, Managed Identities, and Azure Key Vault. Practical experience in SIEM/SOC operations, including Microsoft Sentinel, log analysis, incident investigation, threat hunting, security monitoring, alert triage, and incident response. Good understanding of Identity and Access Management (IAM) in cloud environments, including identity lifecycle management, MFA, Privileged Identity Management (PIM), Conditional Access Policies, and Zero Trust principles.

The candidate will have responsibilities across the following functions:

Security Monitoring and Alert Investigation:

  • Monitor and investigate security alerts, incidents, and security incidents from SIEM platforms and ticketing systems.
  • Analyse and triage Alerts, Incidents, and Security Incidents to determine legitimacy, severity, scope, and impact.
  • Correlate logs and events from multiple security tools including EDR, firewalls, IDS/IPS, cloud platforms, and endpoint systems.
  • Escalate validated threats and critical incidents according to defined procedures.
  • Ensure timely response and resolution within agreed SLAs.

Incident Response (IR) and Security Incident Handling:

  • Execute all stages of the Incident Response lifecycle: Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned
  • Investigate and respond to cybersecurity incidents including malware infections, phishing attacks, unauthorised access, insider threats, and suspicious activities.
  • Perform root cause analysis and determine attack vectors, impacted assets, and remediation actions.
  • Coordinate containment and recovery activities with infrastructure, network, endpoint, and application teams.
  • Maintain proper incident documentation, evidence collection, timelines, and response records.

Support post-incident review and improvement activities.

SIEM Fine-Tuning and Security Engineering:

  • Fine-tune SIEM use cases, correlation rules, parsers, dashboards, and alerting mechanisms.
  • Reduce false positives and improve detection accuracy and operational efficiency.
  • Enhance monitoring visibility by onboarding new log sources and improving telemetry coverage.
  • Identify monitoring gaps and recommend improvements to security controls and detection capabilities.
  • Support automation and security orchestration initiatives.

Threat Hunting:

  • Conduct proactive threat hunting activities to identify advanced threats and hidden malicious behaviour.
  • Utilise threat intelligence, IOC analysis, behavioural analytics, and MITRE ATT& CK techniques during investigations.
  • Develop and execute threat hunting hypotheses and detection queries.
  • Identify anomalous activities and improve detection logic based on findings.
  • Provide recommendations to strengthen the organisation's security posture.

Stakeholder Coordination and Incident Management:

  • Drive and lead incident bridge calls with internal and external stakeholders during active security incidents.
  • Coordinate remediation and recovery activities with technical teams and business owners.
  • Provide regular incident status updates, technical findings, and remediation recommendations.
  • Track remediation actions and ensure timely closure of security incidents.
  • Participate in operational and management reporting activities.

Day-to-Day Activities:

  • Monitor SIEM dashboards, alerts, and incident queues.
  • Investigate suspicious events and validate security alerts.
  • Respond to and manage security incidents following IR processes.
  • Perform log analysis, event correlation, and root cause analysis.
  • Fine-tune SIEM rules and improve detection visibility.
  • Conduct proactive threat hunting and IOC analysis.
  • Lead incident response and remediation coordination calls.
  • Create and maintain SOPs, playbooks, and operational documentation.
  • Update tickets, incident records, and investigation reports.
  • Collaborate with stakeholders to ensure timely remediation and recovery.

Requirements:

  • Strong hands-on experience with Azure Cloud Security, including Microsoft Entra ID (Azure AD), Azure Defender for Cloud, Azure Security Centre, Conditional Access, RBAC, Managed Identities, and Azure Key Vault.
  • Mandatory Skills: Azure Cloud Security, Microsoft Entra ID (Azure AD), Microsoft Sentinel (SIEM), SOC Operations, IAM, Incident Response, and excellent verbal and written communication skills. Candidates with only On-Premises Active Directory experience will not be considered.
  • Operations, IAM, Incident Response, and excellent verbal and written communication skills.
  • Candidates with only On-Premises Active Directory experience will not be considered.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,657 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$19k – $53k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Pune
Bash
JavaScript
Python
TypeScript
Frontend
Angular
React.js
DevOps
AWS
Azure
Datadog
Docker
GCP
Grafana
Kubernetes
Prometheus
Splunk
IAM
Cybersecurity
Keycloak
Apply
SDET 1 day ago
$12k – $39k per year (Estimated) • In office • 4+ years exp • Gurgaon
Java
DevOps
AWS
Azure
CI/CD
Jenkins
QA
Appium
JMeter
Playwright
Rest-Assured
Selenium
Apply
$20k – $45k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Gurgaon
Python
SQL
Python
pySpark
Databases
Databricks
Microsoft Fabric
AI/ML
Hadoop
Spark
DevOps
AWS
Azure
Analytics
Power BI
Tableau
Apply
$67k – $173k per year (Estimated) • In office • Contractor • 3+ years exp • Bachelor's Degree • Singapore
JavaScript
Python
DevOps
AWS
Azure
GCP
Cybersecurity
ISO 27001
OWASP Top 10
Apply
$77k – $194k per year (Estimated) • In office • Contractor • 5+ years exp • Singapore
Java
SQL
DevOps
CI/CD
Docker
Grafana
Incident Management
Kubernetes
OpenShift
SRE
Apply
See all jobs
This is one of many
368,657 more open roles from verified company boards, updated every day.