DIGITAL SECURITY - SOC Services at Zensar Technologies · HyrikoBack to jobsLocation:Hyderabad, Telangana, IndiaType:Full-timePosted:Yesterday Key Responsibilities
Security Monitoring & Incident Detection (Must have)
- Monitor security events and alerts generated from Logpoint SIEM (GuardSIX) and integrated security tools.
- Perform real-time analysis of security incidents and suspicious activities.
- Investigate alerts related to malware, phishing, ransomware, insider threats, privilege misuse, and unauthorized access.
- Validate and triage security alerts based on severity and business impact.
- Escalate incidents to L2 & L3 teams and stakeholders as per defined procedures.
Incident Response & Investigation (Must Have)
- Conduct incident investigations using SIEM queries and threat intelligence sources.
• Analyze logs from:
o Windows Servers & Workstations
o Linux Systems
o Active Directory
o Firewalls
o IDS/IPS
o Proxy and Web Gateways
o EDR/XDR Solutions
o Cloud Platforms (Azure, AWS, GCP)
- Perform root cause analysis and incident documentation.
- Support containment, eradication, and recovery activities.
Threat Hunting & Threat Intelligence (Must have)
Don't want to miss the next one?
Subscribe to daily email alerts for roles matching your interests.
Get email alerts Execute proactive threat hunting activities using Logpoint searches.- Leverage MITRE ATT&CK framework for threat mapping.
- Analyze Indicators of Compromise (IoCs).
- Correlate threat intelligence feeds with internal security events.
- Identify anomalous user and system behaviors.
Logpoint SIEM Administration & Use Case Monitoring (Good to have)
- Create, modify, and tune Logpoint correlation rules and use cases.
- Fine-tune alert thresholds to reduce false positives.
- Develop dashboards, reports, and custom searches.
- Monitor log collection health and data ingestion.
- Validate parser functionality and troubleshoot log collection issues.
- Perform use case validation and testing.
Required Technical Skills
• Hands-on experience with:
o Logpoint SIEM (GuardSIX) – Mandatory
o Experience with Splunk/QRadar/Microsoft Sentinel (Preferred)
- Firewalls (Palo Alto, Fortinet, Check Point, Cisco)
- IDS/IPS (Snort, Suricata, Trend Micro)
- EDR/XDR (Microsoft Defender, CrowdStrike, SentinelOne)
- Vulnerability Management Tools
- Network Security Concepts
- Security Incident Response Lifecycle
- Threat Intelligence Concepts
- Malware Analysis Fundamentals
- Security Monitoring Best Practices
- SOC Processes and Procedures
- Event Correlation Techniques
Qualifications
- Bachelor's Degree in Computer Science, Information Security, IT, or related field.
- 3+ years of experience in SOC operations.
- Experience working in 24x7 rotational shifts.
- Strong analytical and troubleshooting skills.
- Excellent verbal and written communication skills.
- CEH (Certified Ethical Hacker)
- SC-200 (Microsoft Security Operations Analyst)
- Logpoint Certified Analyst (Preferred)
Key Performance Indicators (KPIs)
- Incident Response SLA Compliance
- Mean Time to Detect (MTTD)
- Mean Time to Respond (MTTR)
- Reduction in False Positive Alerts
Key Responsibilities
Security Monitoring & Incident Detection (Must have)
- Monitor security events and alerts generated from Logpoint SIEM (GuardSIX) and integrated security tools.
- Perform real-time analysis of security incidents and suspicious activities.
- Investigate alerts related to malware, phishing, ransomware, insider threats, privilege misuse, and unauthorized access.
- Validate and triage security alerts based on severity and business impact.
- Escalate incidents to L2 & L3 teams and stakeholders as per defined procedures.
Incident Response & Investigation (Must Have)
- Conduct incident investigations using SIEM queries and threat intelligence sources.
• Analyze logs from:
o Windows Servers & Workstations
o Cloud Platforms (Azure, AWS, GCP)
- Perform root cause analysis and incident documentation.
- Support containment, eradication, and recovery activities.
Threat Hunting & Threat Intelligence (Must have)
- Execute proactive threat hunting activities using Logpoint searches.
- Leverage MITRE ATT&CK framework for threat mapping.
- Analyze Indicators of Compromise (IoCs).
- Correlate threat intelligence feeds with internal security events.
- Identify anomalous user and system behaviors.
Logpoint SIEM Administration & Use Case Monitoring (Good to have)
- Create, modify, and tune Logpoint correlation rules and use cases.
- Fine-tune alert thresholds to reduce false positives.
- Develop dashboards, reports, and custom searches.
- Monitor log collection health and data ingestion.
- Validate parser functionality and troubleshoot log collection issues.
- Perform use case validation and testing.
Required Technical Skills
• Hands-on experience with:
o Logpoint SIEM (GuardSIX) – Mandatory
o Experience with Splunk/QRadar/Microsoft Sentinel (Preferred)
- Firewalls (Palo Alto, Fortinet, Check Point, Cisco)
- IDS/IPS (Snort, Suricata, Trend Micro)
- EDR/XDR (Microsoft Defender, CrowdStrike, SentinelOne)
- Vulnerability Management Tools
- Network Security Concepts
- Security Incident Response Lifecycle
- Threat Intelligence Concepts
- Malware Analysis Fundamentals
- Security Monitoring Best Practices
- SOC Processes and Procedures
- Event Correlation Techniques
Qualifications
- Bachelor's Degree in Computer Science, Information Security, IT, or related field.
- 3+ years of experience in SOC operations.
- Experience working in 24x7 rotational shifts.
- Strong analytical and troubleshooting skills.
- Excellent verbal and written communication skills.
- CEH (Certified Ethical Hacker)
- SC-200 (Microsoft Security Operations Analyst)
- Logpoint Certified Analyst (Preferred)
Key Performance Indicators (KPIs)
- Incident Response SLA Compliance
- Mean Time to Detect (MTTD)
- Mean Time to Respond (MTTR)
- Reduction in False Positive Alerts
Key Responsibilities
Security Monitoring & Incident Detection (Must have)
- Monitor security events and alerts generated from Logpoint SIEM (GuardSIX) and integrated security tools.
- Perform real-time analysis of security incidents and suspicious activities.
- Investigate alerts related to malware, phishing, ransomware, insider threats, privilege misuse, and unauthorized access.
- Validate and triage security alerts based on severity and business impact.
- Escalate incidents to L2 & L3 teams and stakeholders as per defined procedures.
Incident Response & Investigation (Must Have)
- Conduct incident investigations using SIEM queries and threat intelligence sources.
• Analyze logs from:
o Windows Servers & Workstations
o Cloud Platforms (Azure, AWS, GCP)
- Perform root cause analysis and incident documentation.
- Support containment, eradication, and recovery activities.
Threat Hunting & Threat Intelligence (Must have)
- Execute proactive threat hunting activities using Logpoint searches.
- Leverage MITRE ATT&CK framework for threat mapping.
- Analyze Indicators of Compromise (IoCs).
- Correlate threat intelligence feeds with internal security events.
- Identify anomalous user and system behaviors.
Logpoint SIEM Administration & Use Case Monitoring (Good to have)
- Create, modify, and tune Logpoint correlation rules and use cases.
- Fine-tune alert thresholds to reduce false positives.
- Develop dashboards, reports, and custom searches.
- Monitor log collection health and data ingestion.
- Validate parser functionality and troubleshoot log collection issues.
- Perform use case validation and testing.
Required Technical Skills
• Hands-on experience with:
o Logpoint SIEM (GuardSIX) – Mandatory
o Experience with Splunk/QRadar/Microsoft Sentinel (Preferred)
- Firewalls (Palo Alto, Fortinet, Check Point, Cisco)
- IDS/IPS (Snort, Suricata, Trend Micro)
- EDR/XDR (Microsoft Defender, CrowdStrike, SentinelOne)
- Vulnerability Management Tools
- Network Security Concepts
- Security Incident Response Lifecycle
- Threat Intelligence Concepts
- Malware Analysis Fundamentals
- Security Monitoring Best Practices
- SOC Processes and Procedures
- Event Correlation Techniques
Qualifications
- Bachelor's Degree in Computer Science, Information Security, IT, or related field.
- 3+ years of experience in SOC operations.
- Experience working in 24x7 rotational shifts.
- Strong analytical and troubleshooting skills.
- Excellent verbal and written communication skills.
- CEH (Certified Ethical Hacker)
- SC-200 (Microsoft Security Operations Analyst)
- Logpoint Certified Analyst (Preferred)
Key Performance Indicators (KPIs)
- Incident Response SLA Compliance
- Mean Time to Detect (MTTD)
- Mean Time to Respond (MTTR)
- Reduction in False Positive Alerts
Similar roles you might like
More openings like this one — take a look before you go.
CCustomer Experience Associate II
Conduent
NewBengaluru, Karnataka, IndiaOn-siteYesterday Full-timecustomer servicecall center operationsdata entry
via Career pages
TData Engineer II (Data Platform)
Tripadvisor
NewOxford, Oxfordshire, United Kingdom Hybrid Or Remote, IndiaRemoteYesterday Full-time
via Career pages
DOperations Executive - IAH
DHL Group
NewBengaluru, Karnataka, IndiaOn-siteYesterday Full-timehub operations managementair network operations
HStrategic Account Executive, DACH
Harvey
NewRemote, Munich, IndiaRemoteYesterday Full-time
via Career pages
Browse all jobsshipment processing