Be an Early Applicant
Helping clients achieve homeownership and financial freedom with simple, fast and trusted digital solutions.
The Role
Monitor and triage security alerts across SIEM, endpoint, email, identity, and cloud platforms. Investigate suspicious activity, analyze phishing and endpoint events, map threats to MITRE ATT&CK, and manage incidents through containment and recovery. Preserve evidence, reconstruct attack timelines, tune detection logic, maintain runbooks, identify automation opportunities, and collaborate on remediation. The role requires flexible availability for evenings, weekends, holidays, and high-severity incidents.
Summary Generated by Built In
At Rocket India, security isn't just a function - it's a promise. Every alert we investigate, every threat we neutralize, and every detection we refine protects the financial futures of millions of families working toward homeownership. Our Security Operations Center operates at the intersection of technology and trust, and we need a sharp, relentless SOC Analyst who sees patterns where others see noise, who treats every signal with the seriousness it deserves, and who's ready to be the shield that never sleeps. If you want your career in cybersecurity to have real-world impact at scale, welcome to the front line.
About the Role
Alert Triage and Investigation
Incident Response
Detection Quality and Continuous Improvement
About You
Minimum Qualifications:
Preferred Qualifications:
What You Will Get
At Rocket India, defending the organization means you're also investing in yourself. You'll operate with industry-leading security tooling, gain exposure to sophisticated threat landscapes, and grow within a team that values curiosity and continuous learning. We provide competitive compensation, comprehensive health coverage, certification sponsorship, and a culture that celebrates the people who keep us safe. Whether it's advancing your credentials, contributing to automation that makes the team faster, or stepping up during critical incidents - every contribution here accelerates your career and protects what matters most.
About Us
Rocket India, registered as NSM Services Private Limited and formerly Mr. Cooper, is a wholly owned subsidiary of Rocket Mortgage, LLC, headquartered in Detroit, Michigan. As a core part of Rocket's global ecosystem, Rocket India helps shape the future of home financing through technology, innovation, operations, product, and customer-focused solutions. Our teams build scalable platforms and digital experiences that simplify mortgage origination and servicing while supporting Rocket's mission to "Help Everyone Home."
We are committed to providing a fair and inclusive workplace for all team members and applicants. All qualified applicants will receive consideration for employment without regard to sex, religion, caste, disability, or gender identity, consistent with applicable Indian law, including the Constitution of India, the Code on Wages, 2019, the Rights of Persons with Disabilities Act, 2016, and the Transgender Persons (Protection of Rights) Act, 2019. We welcome applications from persons with disabilities and from all sections of society.
About the Role
Alert Triage and Investigation
- Serve as the first line of defense by monitoring and triaging alerts across SIEM, endpoint detection and response, email security, identity, and cloud security platforms - always prioritizing by risk and business impact
- Investigate suspicious activity to a definitive conclusion, pivoting across multiple telemetry sources to confirm or rule out malicious behavior
- Map observed activity to a recognized framework such as MITRE ATT&CK, enabling consistent categorization and meaningful trend analysis
- Analyze reported phishing attempts, endpoint detections, identity anomalies, and cloud misconfiguration alerts - meticulously recording findings and reasoning in the case record
- Leverage threat intelligence and malware analysis tooling to assess indicator reputation and observed behavior
- Escalate confirmed or suspected incidents with precision - delivering a clear summary of what is known, what remains unverified, and recommended next steps
Incident Response
- Own incidents below P1 through the full incident response lifecycle - detection and analysis, containment, eradication, recovery, and post-incident review
- Determine blast radius and reconstruct attack timelines by correlating endpoint, identity, network, and log telemetry
- Execute decisive containment actions including host isolation, account disablement, and indicator blocking - escalating when scope or business impact demands it
- Collect and preserve digital evidence with sound chain-of-custody practices
- Support the incident response lead on P1 events by providing scoping intelligence, evidence, and timeline reconstruction
- Maintain thorough incident records and contribute meaningfully to post-incident reviews, after-action reports, and lessons learned
- Collaborate with ThreatOps, SecOps Engineering, IT, and application teams to validate findings and drive coordinated remediation
- Participate in tabletop exercises and response drills to sharpen readiness across the team
Detection Quality and Continuous Improvement
- Tune detection logic to reduce false positives, documenting the rationale and accepted risk for every suppression or threshold change
- Identify recurring alert patterns and surface automation candidates to SecOps Engineering for evaluation and build
- Maintain and enhance triage runbooks to ensure investigative steps are repeatable and consistent across the team
- Report detection coverage gaps uncovered during casework to strengthen the organization's security posture
About You
Minimum Qualifications:
- 1 year in an information security analyst or SOC analyst role
- 3 years of experience in a technology role
- Bachelor's degree in information assurance, computer science, or a related field, or equivalent experience
- Hands-on experience with a SIEM, including log search, correlation, and alert triage across large structured and unstructured data sets
- Working knowledge of endpoint detection and response tooling and the investigative workflow it supports
- Proficiency in operating systems (Windows, macOS, Linux/Unix, mobile) and core network theory, including common protocols and basic traffic analysis
- Ability to read and interpret scripts, and to write basic scripts or queries in support of an investigation
- Familiarity with common attacker techniques and a recognized classification framework such as MITRE ATT&CK
- Working understanding of the incident response lifecycle and the ability to apply it to live incidents
- Clear written communication - able to document an investigation so a colleague can pick it up without a verbal handoff
- Schedule flexibility - must be available to work outside standard business hours, including evenings, weekends, and holidays, as incident severity and volume demand
Preferred Qualifications:
- 3 years in an information security analyst or SOC analyst role
- 5 years of experience in a technology role
- Experience owning incidents through containment and recovery in an enterprise environment
- Demonstrated experience tuning detection logic and measurably reducing false positive volume
- Exposure to security automation or SOAR platforms, with a keen eye for identifying automation opportunities
- Certifications such as Security+, ISC2 credentials (SSCP or CISSP Associate), or GSEC; incident response credentials such as GCIH or GCFA are especially valued
- Experience with cloud security monitoring (AWS, Azure, GCP) and detection of identity-based attacks
- Experience in the mortgage, financial services, or another regulated industry
What You Will Get
At Rocket India, defending the organization means you're also investing in yourself. You'll operate with industry-leading security tooling, gain exposure to sophisticated threat landscapes, and grow within a team that values curiosity and continuous learning. We provide competitive compensation, comprehensive health coverage, certification sponsorship, and a culture that celebrates the people who keep us safe. Whether it's advancing your credentials, contributing to automation that makes the team faster, or stepping up during critical incidents - every contribution here accelerates your career and protects what matters most.
About Us
Rocket India, registered as NSM Services Private Limited and formerly Mr. Cooper, is a wholly owned subsidiary of Rocket Mortgage, LLC, headquartered in Detroit, Michigan. As a core part of Rocket's global ecosystem, Rocket India helps shape the future of home financing through technology, innovation, operations, product, and customer-focused solutions. Our teams build scalable platforms and digital experiences that simplify mortgage origination and servicing while supporting Rocket's mission to "Help Everyone Home."
We are committed to providing a fair and inclusive workplace for all team members and applicants. All qualified applicants will receive consideration for employment without regard to sex, religion, caste, disability, or gender identity, consistent with applicable Indian law, including the Constitution of India, the Code on Wages, 2019, the Rights of Persons with Disabilities Act, 2016, and the Transgender Persons (Protection of Rights) Act, 2019. We welcome applications from persons with disabilities and from all sections of society.
Skills Required
- At least 1 year of experience in an information security analyst or SOC analyst role
- At least 3 years of experience in a technology role
- Bachelor's degree in information assurance, computer science, or a related field, or equivalent experience
- Hands-on experience with a SIEM, including log search, correlation, and alert triage across structured and unstructured data sets
- Working knowledge of endpoint detection and response tooling and related investigative workflows
- Proficiency with Windows, macOS, Linux/Unix, mobile operating systems, core network theory, common protocols, and basic traffic analysis
- Ability to read and interpret scripts and write basic scripts or queries for investigations
- Familiarity with attacker techniques and a recognized classification framework such as MITRE ATT&CK
- Working understanding of the incident response lifecycle and ability to apply it to live incidents
- Clear written communication and ability to document investigations thoroughly
- Availability to work outside standard business hours, including evenings, weekends, and holidays
- At least 3 years of experience in an information security analyst or SOC analyst role
- At least 5 years of experience in a technology role
- Experience owning enterprise incidents through containment and recovery
- Experience tuning detection logic and reducing false-positive volume
- Exposure to security automation or SOAR platforms
- Security+, ISC2 SSCP, CISSP Associate, GSEC, GCIH, or GCFA certification
- Experience with cloud security monitoring across AWS, Azure, or GCP and identity-based attack detection
- Experience in mortgage, financial services, or another regulated industry
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Rocket Companies® is a Detroit-based company made up of businesses that provide simple, fast and trusted digital solutions for complex transactions. The name comes from our flagship business, now known as Rocket Mortgage®, which was founded in 1985. Today, we’re a publicly traded company involved in many different industries, including mortgages, fintech, real estate, automotive and more. We’re insistently different in how we look at the world and committed to an inclusive workplace where every voice is heard.
Rocket Companies Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
Typical time on-site:
Not Specified
