TC

SOC Analyst L2

Accepting applications

Tata Consultancy Services · Chennai, Tamil Nadu, India

Full-Time Mid_senior SOC
Posted
1d ago
Category
Design
Experience
Mid_senior
Country
India
Job description
Role & responsibilities
SOC Analyst L2
Security Monitoring & Incident Response
Execute/lead initial containment, forensics scoping, and stakeholder updates; align with both best industry practice and internal IR playbooks.
Lead investigations across Defender XDR/MDE and CrowdStrike (process trees, lateral movement, identity signals).
Use Tanium for rapid endpoint scoping and live response actions (as per policy).
Analyse Joe Sandbox reports (behaviour trees, network indicators, dropped files); derive IOCs/YARA candidates; coordinate containment.
Design/maintain Cortex XSOAR playbooks (data enrichment, containment workflows, approvals, notifications); implement guardrails.

Threat Detection & Hunting
Deep familiarity with Azure AD/Entra ID, Azure Activity/Signin logs, M365 audit logs, as well as AWS and GCP logs.
Author and tune analytic rules in Sentinel (KQL), Elastic (DSL/EQL/KQL/ESQL), Sigma; reduce false positives; add entity mapping and suppression logic.
Proactive hunts using ATT&CK-aligned hypotheses (credential theft, persistence, C2); pivot across endpoint, identity, network, and cloud logs.
Maintain GitLab repos (branching, merge requests, CI checks for detections) and workflows for detection content (code reviews, approvals, CI quality checks).

Expertise:
Deep knowledge of SIEM, SOAR, and EDR platforms
Deep knowledge of threat intelligence, and incident response frameworks
Familiarity with MITRE ATT&CK, NIST, and ISO 27001 standards
Ability to analyse logs, network traffic, and malware indicators



Show more Show less