SecOps Engineer / Security Operations / SOC Engineer

Posted 3 Days Ago
Be an Early Applicant
Gurugram, Haryana, IND
In-Office
Mid level
Cloud • Information Technology • Consulting • Automation
The Role
Investigate and respond to security alerts and incidents across customer cloud, endpoint, identity, network, and SIEM/XDR environments. Responsibilities include threat hunting, detection engineering, incident response, EDR investigation, cloud security monitoring, threat intelligence, vulnerability analysis, and SOC automation. The engineer will improve detection coverage, reduce false positives, support containment and remediation, and map detections to MITRE ATT&CK while meeting customer SLAs.
Summary Generated by Built In
About Infra360
Infra360 is a Managed Cloud Service Provider helping businesses build, secure and operate their cloud and technology environments across Cloud, DevOps, SRE, Security, FinOps and Managed Services.
We are building our Security Operations and MDR capabilities and are looking for a hands-on SecOps Engineer to join the team.

About the Role
As a SecOps Engineer, you will be responsible for security monitoring, alert investigation, threat hunting, detection engineering and incident response across customer environments.
This is not a traditional alert-monitoring role. We are looking for someone who can investigate security events, understand attacker behavior, identify the root cause, improve detections and support effective response.
You will work across SIEM, EDR/XDR, cloud, identity, endpoint and network security telemetry.

Key Responsibilities1. Security Monitoring & Alert Investigation
  • Monitor and investigate security alerts across customer environments.
  • Perform alert triage and determine severity and business impact.
  • Correlate events across endpoint, identity, network and cloud sources.
  • Investigate suspicious activity and identify false positives.
  • Maintain accurate incident timelines and investigation documentation.
  • Work within defined security processes and customer SLAs.
2. SIEM / XDR Operations
  • Work with SIEM/XDR platforms such as Microsoft Sentinel, Microsoft Defender XDR, Wazuh, Splunk, Elastic, CrowdStrike, SentinelOne, Google SecOps or similar.
  • Analyze logs and security telemetry.
  • Develop and tune detection and correlation rules.
  • Monitor log-source health and identify visibility gaps.
  • Improve alert quality and detection coverage.
3. Incident Response
Investigate and support response to incidents including:
  • Malware and ransomware
  • Account compromise
  • Phishing and business email compromise
  • Credential attacks
  • Privilege escalation
  • Lateral movement
  • Suspicious PowerShell/scripts
  • Command-and-control activity
  • Cloud security incidents
  • Data-exfiltration activity
The engineer should be able to understand what happened, how it happened, what is affected and what needs to be done next.
4. Threat Hunting
Conduct proactive threat hunting using:
  • MITRE ATT&CK
  • IOCs and TTPs
  • Suspicious processes
  • Authentication anomalies
  • PowerShell/script activity
  • C2 indicators
  • Credential abuse
  • Cloud activity
Identify threats that may not have been detected through existing alerts.
5. Detection Engineering
  • Develop and improve SIEM detection rules.
  • Create and tune correlation rules.
  • Develop behavioral and IOC-based detections.
  • Map detections to MITRE ATT&CK.
  • Identify detection gaps and improve coverage.
  • Convert incident learnings into new detection use cases.
  • Knowledge of Sigma is preferred.
6. EDR/XDR Investigation
  • Analyze processes, process trees, files, hashes and network connections.
  • Investigate endpoint behavior and persistence mechanisms.
  • Support endpoint isolation and containment.
  • Coordinate remediation with the Security & IT Operations team.
  • Validate endpoint security after remediation.
7. Cloud Security Monitoring
Investigate security events across AWS, Azure and GCP.
Exposure to technologies such as CloudTrail, GuardDuty, Security Hub, IAM, WAF, Microsoft Defender and cloud audit logs is preferred.
The role focuses on security monitoring and investigation, while cloud infrastructure ownership remains with DevOps/SRE.
8. Security Automation
Automate repetitive SOC activities using Python, PowerShell, APIs, SIEM automation or SOAR platforms.
Examples include IOC enrichment, reputation checks, automated ticket creation, alert enrichment and response actions.
9. Threat Intelligence & Vulnerability Analysis
  • Enrich investigations using threat intelligence.
  • Analyze IPs, domains, hashes and malware indicators.
  • Track relevant CVEs and exploitation activity.
  • Support risk-based vulnerability prioritization.
  • Use threat intelligence to improve detections and investigations.

What We're Looking For
Must Have:
  • 3–7 years of experience in SOC, SecOps, MDR, Incident Response or Cybersecurity.
  • Strong hands-on SIEM experience.
  • Experience with EDR/XDR platforms.
  • Experience investigating security incidents.
  • Strong networking fundamentals.
  • Good Windows and Linux security knowledge.
  • Understanding of IAM and authentication.
  • Understanding of common attack techniques.
  • Incident-response experience.
  • Good understanding of MITRE ATT&CK.
  • Strong analytical and troubleshooting skills.
Good to Have:
  • MDR/MSSP experience.
  • Threat hunting experience.
  • Detection engineering.
  • Sigma/YARA knowledge.
  • Python or scripting.
  • AWS/Azure/GCP security experience.
  • Kubernetes/container security exposure.
  • SOAR experience.
  • Experience handling multiple customers or tenants.

What Success Looks Like
In this role, success means being able to detect, investigate and respond to security threats effectively, while continuously improving Infra360's MDR capabilities.
You will contribute to better detection coverage, faster response, fewer false positives, stronger threat hunting and more effective security operations across customer environments.

Skills Required

  • 3-7 years of experience in SOC, SecOps, MDR, incident response, or cybersecurity
  • Strong hands-on SIEM experience
  • Experience with EDR/XDR platforms
  • Experience investigating security incidents
  • Strong networking fundamentals
  • Windows and Linux security knowledge
  • Understanding of IAM and authentication
  • Understanding of common attack techniques
  • Incident-response experience
  • Understanding of MITRE ATT&CK
  • Strong analytical and troubleshooting skills
  • MDR or MSSP experience
  • Threat hunting experience
  • Detection engineering experience
  • Sigma or YARA knowledge
  • Python or scripting experience
  • AWS, Azure, or GCP security experience
  • Kubernetes or container security exposure
  • SOAR experience
  • Experience handling multiple customers or tenants
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
39 Employees

What We Do

Infra360 is a fast-growing cloud, DevOps, and infrastructure services company headquartered in Gurugram (Gurgaon), India, that helps startups and enterprises modernize, secure, and scale their platforms across AWS, Azure, and GCP. Founded in 2022 by Deepak Agrawal, it provides customer-centric cloud consulting for technology-driven organizations, focusing on cloud excellence and business resilience, and is recognized as a DPIIT-recognized startup.

Similar Jobs

Optum Logo Optum

Data Analyst

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Gurgaon, Gurugram, Haryana, IND
160000 Employees

Optum Logo Optum

Scrum Lead

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Gurgaon, Gurugram, Haryana, IND
160000 Employees

Optum Logo Optum

Senior Data Analyst

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Gurgaon, Gurugram, Haryana, IND
160000 Employees

Optum Logo Optum

Machine Learning Engineer

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Gurgaon, Gurugram, Haryana, IND
160000 Employees

Similar Companies Hiring

Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account