HC
Information Security Analyst - Level 2
Accepting applicationsHitachi Cyber · Pune Division, Maharashtra, India
Full-Time Associate MentorSOC
Posted
1d ago
Category
Design
Experience
Associate
Country
India
Join Hitachi Cyber and play a key role in protecting organizations through advanced security monitoring and incident response.
We are looking for an Information Security Analyst (Level 2) to play a key role in our Security Operations Center (SOC), serving as the primary escalation point for security incidents and supporting the organization's cyber defense capabilities.
The ISA L2 will ensure timely and effective detection, investigation, and response to security incidents. The role is responsible for performing advanced incident analysis, determining appropriate escalation paths, and coordinating with the TSS and Detection Engineering teams to support continuous improvement of security operations and threat detection capabilities.
Here’s an overview of your main responsibilities:
Monitor, investigate, and respond to security alerts and incidents generated through SIEM, XDR, and security monitoring platforms such as Microsoft Sentinel, Google SecOps, Microsoft Defender, MDR/XDR platforms, and similar technologies.
Ensure incidents are detected, tracked, documented, and resolved within defined SLAs.
Investigate incidents escalated by Level 1 Analysts and perform detailed event correlation and root cause analysis.
Follow established escalation procedures and escalate incidents to the appropriate teams when required.
Mentor and support Level 1 Analysts to improve analytical and investigation capabilities.
Update and maintain SOC documentation, procedures, knowledge articles, and collaboration platforms (e.g., Confluence).
Coordinate with the Detection Engineering Team for SIEM tuning, alert optimization, use case validation, and false-positive reduction.
Perform incident response and containment activities using approved security tools and procedures.
Validate the relevance and accuracy of security alerts and coordinate improvements where necessary.
Leverage threat intelligence and Indicators of Compromise (IOCs) during investigations.
Map attacker techniques and incident findings to the MITRE ATT&CK Framework.
Handle customer and stakeholder communications related to security incidents and investigations.
This role may require support for 24x7 security operations, including rotational shifts, on-call support, and shift handovers as applicable.
Exposure to threat hunting activities and methodologies is desirable.
If you recognize yourself in the following, we’d love to meet you:
Bachelor’s degree in computer science, Information Security, Cyber Security, Information Technology, or a related field.
3-4 years of experience in a Security Operations Center (SOC) environment.
Minimum 2 years of hands-on experience with enterprise SIEM platforms, preferably Microsoft Sentinel.
Minimum 1 year of experience with cloud-native security operations platforms such as Google SecOps (Chronicle) or equivalent technologies.
Strong understanding of security monitoring, alert triage, incident investigation, and incident response processes.
Knowledge of Kusto Query Language (KQL) and familiarity with YARA-L.
Good understanding of the MITRE ATT&CK Framework, threat intelligence, and Indicators of Compromise (IOCs).
Experience investigating endpoint, identity, cloud, email, and network security incidents.
Hands-on exposure to Microsoft Defender Suite, Google SecOps, Cybereason, or similar endpoint detection and response solutions.
Solid understanding of risk assessment and vulnerability management.
Excellent verbal and written communication skills in English, including technical documentation and incident reporting.
Ability to work in a 24/7 Security Operations Center (SOC) environment.
Willing to work Overtime, Stay on Standby role (On-Call).
Preferred Certifications
Microsoft Certified: Security Operations Analyst Associate (SC-200)
Microsoft Azure Security Engineer Associate (AZ-500)
Google Cloud Certified - Professional Cloud Security Engineer
Google Cloud Certified - Professional Cloud Security Operations Engineer
CompTIA Security+
Other Microsoft Security Certifications related to Security Operations, Incident Response, or Cloud Security.
What we offer:
Thorough in-house, expert training on cutting-edge technology
Employee Referral Bonus
Group insurance plan
Team spirit and dedication to service excellence
A sense of belonging to a global, brand-name organization
Thank you for your interest in this position. Only candidates selected for further consideration will be contacted.
Show more Show less
We are looking for an Information Security Analyst (Level 2) to play a key role in our Security Operations Center (SOC), serving as the primary escalation point for security incidents and supporting the organization's cyber defense capabilities.
The ISA L2 will ensure timely and effective detection, investigation, and response to security incidents. The role is responsible for performing advanced incident analysis, determining appropriate escalation paths, and coordinating with the TSS and Detection Engineering teams to support continuous improvement of security operations and threat detection capabilities.
Here’s an overview of your main responsibilities:
Monitor, investigate, and respond to security alerts and incidents generated through SIEM, XDR, and security monitoring platforms such as Microsoft Sentinel, Google SecOps, Microsoft Defender, MDR/XDR platforms, and similar technologies.
Ensure incidents are detected, tracked, documented, and resolved within defined SLAs.
Investigate incidents escalated by Level 1 Analysts and perform detailed event correlation and root cause analysis.
Follow established escalation procedures and escalate incidents to the appropriate teams when required.
Mentor and support Level 1 Analysts to improve analytical and investigation capabilities.
Update and maintain SOC documentation, procedures, knowledge articles, and collaboration platforms (e.g., Confluence).
Coordinate with the Detection Engineering Team for SIEM tuning, alert optimization, use case validation, and false-positive reduction.
Perform incident response and containment activities using approved security tools and procedures.
Validate the relevance and accuracy of security alerts and coordinate improvements where necessary.
Leverage threat intelligence and Indicators of Compromise (IOCs) during investigations.
Map attacker techniques and incident findings to the MITRE ATT&CK Framework.
Handle customer and stakeholder communications related to security incidents and investigations.
This role may require support for 24x7 security operations, including rotational shifts, on-call support, and shift handovers as applicable.
Exposure to threat hunting activities and methodologies is desirable.
If you recognize yourself in the following, we’d love to meet you:
Bachelor’s degree in computer science, Information Security, Cyber Security, Information Technology, or a related field.
3-4 years of experience in a Security Operations Center (SOC) environment.
Minimum 2 years of hands-on experience with enterprise SIEM platforms, preferably Microsoft Sentinel.
Minimum 1 year of experience with cloud-native security operations platforms such as Google SecOps (Chronicle) or equivalent technologies.
Strong understanding of security monitoring, alert triage, incident investigation, and incident response processes.
Knowledge of Kusto Query Language (KQL) and familiarity with YARA-L.
Good understanding of the MITRE ATT&CK Framework, threat intelligence, and Indicators of Compromise (IOCs).
Experience investigating endpoint, identity, cloud, email, and network security incidents.
Hands-on exposure to Microsoft Defender Suite, Google SecOps, Cybereason, or similar endpoint detection and response solutions.
Solid understanding of risk assessment and vulnerability management.
Excellent verbal and written communication skills in English, including technical documentation and incident reporting.
Ability to work in a 24/7 Security Operations Center (SOC) environment.
Willing to work Overtime, Stay on Standby role (On-Call).
Preferred Certifications
Microsoft Certified: Security Operations Analyst Associate (SC-200)
Microsoft Azure Security Engineer Associate (AZ-500)
Google Cloud Certified - Professional Cloud Security Engineer
Google Cloud Certified - Professional Cloud Security Operations Engineer
CompTIA Security+
Other Microsoft Security Certifications related to Security Operations, Incident Response, or Cloud Security.
What we offer:
Thorough in-house, expert training on cutting-edge technology
Employee Referral Bonus
Group insurance plan
Team spirit and dedication to service excellence
A sense of belonging to a global, brand-name organization
Thank you for your interest in this position. Only candidates selected for further consideration will be contacted.
Show more Show less