Be an Early Applicant
Helping clients achieve homeownership and financial freedom with simple, fast and trusted digital solutions.
The Role
Monitor and investigate security alerts across SIEM, endpoint, identity, email, network, and cloud sources. Respond to incidents through containment and recovery, preserve evidence, reconstruct attack timelines, and document findings. Tune detection logic, reduce false positives, maintain investigation runbooks, identify automation opportunities, and report coverage gaps. The role partners with security, IT, and application teams, supports critical incidents, and participates in tabletop exercises and response drills.
Summary Generated by Built In
At Rocket India, we're not just building technology - we're building trust. Every transaction, every data point, every customer interaction is protected by the people who refuse to let threats go unanswered. Our Security Operations Center is the nerve center of that mission, and we're looking for a vigilant, curious, and driven SOC Analyst to stand as our first line of defense. If you thrive in fast-paced environments, love piecing together the puzzle of suspicious activity, and want your work to directly safeguard the dream of homeownership for millions - this is your moment.
About the Role
Alert Triage and Investigation
Incident Response
Detection Quality and Continuous Improvement
About You
Minimum Qualifications:
Preferred Qualifications:
What You Will Get
At Rocket India, you'll join a security team that doesn't just react - it evolves. You'll have access to best-in-class security tooling, continuous learning opportunities, and a collaborative culture where your insights directly shape how we protect our business and our clients. We offer competitive compensation, comprehensive health benefits, flexible work arrangements, and investment in your professional development through certifications, training, and mentorship. Your vigilance keeps millions of homeowners safe, and we make sure you're recognized and rewarded for it.
About Us
Rocket India, registered as NSM Services Private Limited and formerly Mr. Cooper, is a wholly owned subsidiary of Rocket Mortgage, LLC, headquartered in Detroit, Michigan. As a core part of Rocket's global ecosystem, Rocket India helps shape the future of home financing through technology, innovation, operations, product, and customer-focused solutions. Our teams build scalable platforms and digital experiences that simplify mortgage origination and servicing while supporting Rocket's mission to "Help Everyone Home."
We are committed to providing a fair and inclusive workplace for all team members and applicants. All qualified applicants will receive consideration for employment without regard to sex, religion, caste, disability, or gender identity, consistent with applicable Indian law, including the Constitution of India, the Code on Wages, 2019, the Rights of Persons with Disabilities Act, 2016, and the Transgender Persons (Protection of Rights) Act, 2019. We welcome applications from persons with disabilities and from all sections of society.
About the Role
Alert Triage and Investigation
- Monitor and triage alerts across SIEM, endpoint detection and response, email security, identity, and cloud security platforms, prioritizing by risk and potential business impact
- Investigate suspicious activity to a conclusion, pivoting across multiple telemetry sources to confirm or rule out malicious behavior
- Classify observed activity against a recognized framework such as MITRE ATT&CK to support consistent categorization and trend analysis
- Analyze reported phishing, endpoint detections, identity anomalies, and cloud misconfiguration alerts, recording findings and reasoning in the case record
- Review indicators using threat intelligence and malware analysis tooling to establish reputation and observed behavior
- Escalate confirmed or suspected incidents promptly, with a clear summary of what is known, what remains unverified, and recommended next steps
Incident Response
- Apply the incident response lifecycle - detection and analysis, containment, eradication, recovery, and post-incident review - to owned incidents
- Determine blast radius and reconstruct attack timelines by correlating endpoint, identity, network, and log telemetry
- Execute containment actions such as host isolation, account disablement, and indicator blocking, escalating when scope or business impact exceeds the severity threshold for independent action
- Collect and preserve evidence, maintaining sound chain of custody
- Support the incident response lead on P1 incidents by providing scoping, evidence, and timeline reconstruction
- Maintain the incident record throughout an event and contribute to post-incident reviews, after-action reports, and lessons learned
- Partner with ThreatOps, SecOps Engineering, IT, and application teams to validate findings and coordinate remediation
- Participate in tabletop exercises and response drills to build and maintain readiness
Detection Quality and Continuous Improvement
- Tune detection logic to reduce false positives, documenting the rationale and the risk accepted for every suppression or threshold change
- Track recurring alert patterns and identify candidates for automation, submitting them to SecOps Engineering for evaluation and build
- Maintain and improve triage runbooks so investigative steps are repeatable across the team
- Report detection coverage gaps observed during casework so they can be addressed
About You
Minimum Qualifications:
- 1 year in an information security analyst or SOC analyst role
- 3 years of experience in a technology role
- Bachelor's degree in information assurance, computer science, or a related field, or equivalent experience
- Hands-on experience with a SIEM, including log search, correlation, and alert triage across large structured and unstructured data sets
- Working knowledge of endpoint detection and response tooling and the investigative workflow it supports
- Proficiency in operating systems (Windows, macOS, Linux/Unix, mobile) and core network theory, including common protocols and basic traffic analysis
- Ability to read and interpret scripts, and to write basic scripts or queries in support of an investigation
- Familiarity with common attacker techniques and a recognized classification framework such as MITRE ATT&CK
- Working understanding of the incident response lifecycle and the ability to apply it to live incidents
- Clear written communication - able to document an investigation so a colleague can pick it up without a verbal handoff
- Schedule flexibility - must be available to work outside standard business hours, including evenings, weekends, and holidays, as incident severity and volume demand
Preferred Qualifications:
- 4 years in an information security analyst or SOC analyst role
- 6 years of experience in a technology role
- Experience owning incidents through containment and recovery in an enterprise environment
- Demonstrated experience tuning detection logic and measurably reducing false positive volume
- Exposure to security automation or SOAR platforms, with an eye for identifying automation opportunities
- Certifications such as Security+, ISC2 credentials (SSCP or CISSP Associate), or GSEC; incident response credentials such as GCIH or GCFA are especially valued
- Experience with cloud security monitoring (AWS, Azure, GCP) and detection of identity-based attacks
- Experience in the mortgage, financial services, or another regulated industry
What You Will Get
At Rocket India, you'll join a security team that doesn't just react - it evolves. You'll have access to best-in-class security tooling, continuous learning opportunities, and a collaborative culture where your insights directly shape how we protect our business and our clients. We offer competitive compensation, comprehensive health benefits, flexible work arrangements, and investment in your professional development through certifications, training, and mentorship. Your vigilance keeps millions of homeowners safe, and we make sure you're recognized and rewarded for it.
About Us
Rocket India, registered as NSM Services Private Limited and formerly Mr. Cooper, is a wholly owned subsidiary of Rocket Mortgage, LLC, headquartered in Detroit, Michigan. As a core part of Rocket's global ecosystem, Rocket India helps shape the future of home financing through technology, innovation, operations, product, and customer-focused solutions. Our teams build scalable platforms and digital experiences that simplify mortgage origination and servicing while supporting Rocket's mission to "Help Everyone Home."
We are committed to providing a fair and inclusive workplace for all team members and applicants. All qualified applicants will receive consideration for employment without regard to sex, religion, caste, disability, or gender identity, consistent with applicable Indian law, including the Constitution of India, the Code on Wages, 2019, the Rights of Persons with Disabilities Act, 2016, and the Transgender Persons (Protection of Rights) Act, 2019. We welcome applications from persons with disabilities and from all sections of society.
Skills Required
- At least 1 year of experience in an information security analyst or SOC analyst role
- At least 3 years of experience in a technology role
- Bachelor's degree in information assurance, computer science, or a related field, or equivalent experience
- Hands-on SIEM experience, including log search, correlation, and alert triage across structured and unstructured data
- Working knowledge of endpoint detection and response tooling and investigative workflows
- Proficiency with Windows, macOS, Linux/Unix, mobile operating systems, network theory, common protocols, and basic traffic analysis
- Ability to interpret scripts and write basic scripts or queries for investigations
- Familiarity with attacker techniques and a framework such as MITRE ATT&CK
- Working understanding of the incident response lifecycle and ability to apply it to live incidents
- Clear written communication and investigation documentation skills
- Availability outside standard business hours, including evenings, weekends, and holidays
- At least 4 years of information security analyst or SOC analyst experience
- At least 6 years of technology experience
- Experience owning enterprise incidents through containment and recovery
- Experience tuning detection logic and reducing false-positive volume
- Exposure to security automation or SOAR platforms
- Security certifications such as Security+, SSCP, CISSP Associate, GSEC, GCIH, or GCFA
- Experience with cloud security monitoring across AWS, Azure, or GCP and identity-based attack detection
- Experience in mortgage, financial services, or another regulated industry
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Rocket Companies® is a Detroit-based company made up of businesses that provide simple, fast and trusted digital solutions for complex transactions. The name comes from our flagship business, now known as Rocket Mortgage®, which was founded in 1985. Today, we’re a publicly traded company involved in many different industries, including mortgages, fintech, real estate, automotive and more. We’re insistently different in how we look at the world and committed to an inclusive workplace where every voice is heard.
Rocket Companies Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
Typical time on-site:
Not Specified
