Sr. Security Operations Analyst

Posted 4 Days Ago
Be an Early Applicant
Noida, Gautam Buddha Nagar, Uttar Pradesh, IND
In-Office
Senior level
Artificial Intelligence • Information Technology • Software • Analytics
The Role
Leads security operations through detection engineering, SIEM and EDR monitoring, threat hunting, incident investigation, containment, and high-severity incident command. Tunes detection rules, investigates phishing and business email compromise, develops automated playbooks, documents cases, and tracks SOC metrics. The role supports continuous improvement, cross-functional coordination, and 24/7 SOC operations while applying threat intelligence and MITRE ATT&CK techniques.
Summary Generated by Built In
Role Overview
We are seeking a highly technical and proactive Sr. Security Operations Analyst to join our Information Security team. In this role you will engineer and mature our security operations infrastructure — designing automated playbooks, tuning advanced telemetry across SIEM, EDR, and cloud environments, and leading high-severity incident containment. As a senior member of the team, you will define triage standards and elevate the technical capability of the wider SOC.

Responsibilities

  • Detection engineering: Architect and optimize real-time detection engineering playbooks across SIEM, EDR, and cloud security platforms to minimize false positives, accelerate triage, and scale threat-hunting capability.
  • Investigation: Investigate suspicious activity, correlate findings across data sources, and document clear, timely case notes for each alert or incident.
  • Incident command: Lead the response lifecycle for high-severity incidents as primary investigator or incident commander, ensuring seamless coordination and technical handoff across cross-functional teams.
  • Containment: Execute containment actions under established playbooks, including endpoint isolation, disabling compromised accounts, and blocking malicious indicators.
  • Threat hunting: Research indicators of compromise and apply threat intelligence to identify anomalous behavior.
  • Rule tuning: Tune detection rules and use cases to reduce false positives and close visibility gaps, in coordination with engineering.
  • Email threats: Investigate and remediate email-based threats such as phishing and business email compromise, from both user submissions and automated detection.
  • Continuous improvement: Contribute to post-incident reviews and metrics reporting — MTTD, MTTR, alert volume, and false-positive rate — to support ongoing SOC maturity.
  • Currency: Stay current on emerging threats, attacker TTPs, and industry frameworks such as MITRE ATT&CK.

Requirements

  • SIEM platforms
  • Splunk
  • Microsoft Sentinel
  • QRadar
  • EDR platforms
  • CrowdStrike
  • Microsoft Defender for Endpoint
  • SentinelOne
  • Windows operating systems
  • Linux operating systems
  • TCP/IP
  • DNS
  • Firewalls
  • Network proxies
  • Incident response
  • Threat hunting
  • Detection engineering
  • Log analysis
  • MITRE ATT&CK framework
  • Phishing investigation
  • Business email compromise
  • Written communication
  • Case documentation

Preferred Skills

  • AWS
  • Azure
  • GCP
  • Cloud security
  • SOAR platforms
  • Python
  • PowerShell
  • KQL
  • SPL
  • Security automation
  • Playbook development

Qualifications

  • 4–6 years of IT or security experience, including hands-on exposure to a SOC, security help desk, or systems administration environment
  • 3+ years monitoring or investigating alerts using a SIEM (e.g., Splunk, Sentinel, QRadar) and an EDR platform (e.g., CrowdStrike, Defender for Endpoint, SentinelOne)
  • Working knowledge of Windows and Linux operating systems, including common attack surfaces and log sources such as event logs, auth logs, and process telemetry
  • Foundational understanding of networking concepts (TCP/IP, DNS, proxies, firewalls) and the protocols relevant to intrusion detection
  • Strong attention to detail, sound judgment under time pressure, and clear written communication for case documentation and shift handoffs
  • Ability to work effectively in a 24/7 SOC rotation, including scheduled shifts and periodic on-call coverage
  • Bachelor's degree in Cybersecurity, Information Technology, or a related field — or equivalent hands-on experience
  • Foundational certifications such as CompTIA Security+ or CySA+ are expected; progress toward GIAC (GCIH, GFACT) or similar is a plus

Skills Required

  • 4-6 years of IT or security experience, including hands-on SOC, security help desk, or systems administration experience
  • 3+ years monitoring or investigating alerts using SIEM and EDR platforms
  • Experience with SIEM platforms such as Splunk, Microsoft Sentinel, or QRadar
  • Experience with EDR platforms such as CrowdStrike, Microsoft Defender for Endpoint, or SentinelOne
  • Working knowledge of Windows and Linux operating systems, including attack surfaces and log sources
  • Foundational knowledge of TCP/IP, DNS, network proxies, firewalls, and intrusion-detection protocols
  • Incident response, threat hunting, detection engineering, log analysis, phishing investigation, and business email compromise experience
  • Strong attention to detail, sound judgment under time pressure, and clear written communication
  • Ability to work in a 24/7 SOC rotation with scheduled shifts and periodic on-call coverage
  • Bachelor's degree in Cybersecurity, Information Technology, or a related field, or equivalent hands-on experience
  • CompTIA Security+ or CySA+ certification
  • AWS, Azure, GCP, cloud security, SOAR, Python, PowerShell, KQL, SPL, security automation, or playbook development
  • Progress toward GIAC GCIH, GFACT, or similar certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
350 Employees
Year Founded: 2025

What We Do

Simfluent builds and operates global capability centers for modern enterprises. It creates fully integrated hubs that function as permanent extensions of clients’ businesses, with capabilities spanning engineering and platforms, cloud, architecture, product, data, and AI. Through greenfield, build-operate-transfer, and hybrid models, Simfluent helps organizations scale technology delivery while preserving quality, culture, strategic alignment, and local control, with predictable execution at enterprise scale.

Similar Jobs

Optum Logo Optum

Senior Capability analyst

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Noida, Gautam Buddha Nagar, Uttar Pradesh, IND
160000 Employees

Optum Logo Optum

Senior Manager AI or ML Engineering

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Noida, Gautam Buddha Nagar, Uttar Pradesh, IND
160000 Employees

Optum Logo Optum

Senior Software Engineer

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Noida, Gautam Buddha Nagar, Uttar Pradesh, IND
160000 Employees

Ericsson Logo Ericsson

Business Support & Charging System

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
Noida, Gautam Buddha Nagar, Uttar Pradesh, IND
88000 Employees

Similar Companies Hiring

Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account