Sr. Security Operations Analyst

Location
Noida, Uttar Pradesh
Workplace
On-site

About this role

Role Overview

We are seeking a highly technical and proactive Sr. Security Operations Analyst to join our Information Security team. In this role you will engineer and mature our security operations infrastructure — designing automated playbooks, tuning advanced telemetry across SIEM, EDR, and cloud environments, and leading high-severity incident containment. As a senior member of the team, you will define triage standards and elevate the technical capability of the wider SOC.

\nResponsibilities
  • Detection engineering: Architect and optimize real-time detection engineering playbooks across SIEM, EDR, and cloud security platforms to minimize false positives, accelerate triage, and scale threat-hunting capability.
  • Investigation: Investigate suspicious activity, correlate findings across data sources, and document clear, timely case notes for each alert or incident.
  • Incident command: Lead the response lifecycle for high-severity incidents as primary investigator or incident commander, ensuring seamless coordination and technical handoff across cross-functional teams.
  • Containment: Execute containment actions under established playbooks, including endpoint isolation, disabling compromised accounts, and blocking malicious indicators.
  • Threat hunting: Research indicators of compromise and apply threat intelligence to identify anomalous behavior.
  • Rule tuning: Tune detection rules and use cases to reduce false positives and close visibility gaps, in coordination with engineering.
  • Email threats: Investigate and remediate email-based threats such as phishing and business email compromise, from both user submissions and automated detection.
  • Continuous improvement: Contribute to post-incident reviews and metrics reporting — MTTD, MTTR, alert volume, and false-positive rate — to support ongoing SOC maturity.
  • Currency: Stay current on emerging threats, attacker TTPs, and industry frameworks such as MITRE ATT&CK.
Requirements
  • SIEM platforms
  • Splunk
  • Microsoft Sentinel
  • QRadar
  • EDR platforms
  • CrowdStrike
  • Microsoft Defender for Endpoint
  • SentinelOne
  • Windows operating systems
  • Linux operating systems
  • TCP/IP
  • DNS
  • Firewalls
  • Network proxies
  • Incident response
  • Threat hunting
  • Detection engineering
  • Log analysis
  • MITRE ATT&CK framework
  • Phishing investigation
  • Business email compromise
  • Written communication
  • Case documentation
Preferred Skills
  • AWS
  • Azure
  • GCP
  • Cloud security
  • SOAR platforms
  • Python
  • PowerShell
  • KQL
  • SPL
  • Security automation
  • Playbook development
Qualifications
  • 4–6 years of IT or security experience, including hands-on exposure to a SOC, security help desk, or systems administration environment
  • 3+ years monitoring or investigating alerts using a SIEM (e.g., Splunk, Sentinel, QRadar) and an EDR platform (e.g., CrowdStrike, Defender for Endpoint, SentinelOne)
  • Working knowledge of Windows and Linux operating systems, including common attack surfaces and log sources such as event logs, auth logs, and process telemetry
  • Foundational understanding of networking concepts (TCP/IP, DNS, proxies, firewalls) and the protocols relevant to intrusion detection
  • Strong attention to detail, sound judgment under time pressure, and clear written communication for case documentation and shift handoffs
  • Ability to work effectively in a 24/7 SOC rotation, including scheduled shifts and periodic on-call coverage
  • Bachelor's degree in Cybersecurity, Information Technology, or a related field — or equivalent hands-on experience
  • Foundational certifications such as CompTIA Security+ or CySA+ are expected; progress toward GIAC (GCIH, GFACT) or similar is a plus
\n

Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?