SOC Analyst L3

8 hours ago


Noida, Uttar Pradesh, India Sanganan IT Solutions Pvt Ltd. Full time ₹ 12,00,000 - ₹ 36,00,000 per year

Job Title:
Level 3 Security Operations Center (SOC) Analyst

Job Type:
 Full Time

Job Location:

  • WORK FROM NOIDA OFFICE, PLEASE DON'T APPLY IF YOU ARE LOOKING FOR HYBRID OR WORK FROM HOME
  • Short notice period or immediate joiners are preferred.

SOC Analyst L3

Job Title:
Level 3 Security Operations Center (SOC) Analyst

Job Type:
Full-Time / Contract

Job Overview:

As a Level 3 SOC Analyst, you will lead advanced threat hunting, detection engineering, and incident response planning activities within a 24/7 MSSP environment. You'll act as a strategic escalation point for complex incidents and bridge threat intelligence, engineering, and client-facing security functions. You will also be responsible for delivering high-impact deliverables, such as Threat Intelligence Digests, Alert Tuning Reports, and Customer-Facing Security Presentations—all aligned to operational SLAs and governance frameworks.

This role requires strong leadership, technical expertise in modern SIEM and EDR platforms (especially Microsoft Sentinel), and experience in executing MSSP service delivery obligations, including IR tabletop exercises, SLA/KPI dashboards, and quarterly threat reviews.

Key Responsibilities:

1. Advanced Threat Hunting & Detection Engineering

  • Lead targeted threat hunting activities based on hypotheses and threat intelligence using KQL, MITRE ATT&CK, and behavioral analytics.
  • Design and develop advanced detection content (Sigma rules, UEBA baselines, custom rules) across SIEM and EDR platforms.
  • Identify and close detection gaps through continuous telemetry analysis and logic refinement.
  • Coordinate log source visibility reviews, baselining, and high-fidelity use case design.

2. Threat Intelligence & Operational Reporting

  • Produce and distribute Weekly Threat Intelligence Digests summarizing current threats, attack trends, and IOCs relevant to customer environments.
  • Map observed activities to TTPs and threat actor profiles.
  • Maintain threat dashboards and feed integrations to support proactive defense.

3. Alert Tuning & Detection Optimization

  • Lead biweekly Alert Tuning efforts to analyze false positives, adjust thresholds, and suppress noisy detections.
  • Deliver a formal Biweekly Alert Tuning Report outlining tuning actions, impact assessments, and next steps.
  • Collaborate with content authors to implement rule changes and push updates to production environments via controlled change processes.

4. Incident Response Leadership & Crisis Escalation

  • Serve as the final escalation point for Priority 1 (P1) or crisis-level incidents, ensuring incident bridge calls, executive reporting, and customer coordination occur within SLA timelines.
  • Perform deep-dive investigations into root causes and adversary techniques.
  • Own incident post-mortems and RCA (Root Cause Analysis) documentation.
  • Ensure compliance with the IR lifecycle from detection to closure, with audit-ready documentation.

5. MSSP Reporting & Executive Briefings

  • Prepare and deliver Monthly and Quarterly Security Reports to MSSP clients covering:
  • Alert trends, threat landscape updates, SLA/KPI dashboards
  • Executive summaries, incident breakdowns, and risk remediation insights
  • Present findings to customer stakeholders via scheduled service review meetings and executive briefings.
  • Ensure SLA compliance targets are tracked and reported, including MTTD, MTTR, escalation compliance, and false positive rates.

6. IR Tabletop Exercise Management

  • Plan, facilitate, and report on Quarterly Incident Response Tabletop Exercises with internal and external stakeholders.
  • Develop realistic, role-based tabletop scenarios (ransomware, insider threat, data exfiltration, etc.).
  • Deliver Tabletop Exercise Reports with participant feedback, lessons learned, and actionable improvements.

7. SOC Governance & Pre-Onboarding Support

  • Contribute to MSSP onboarding by helping define:
  • Log source mapping and ingestion validation
  • Detection rule baselines, alert taxonomy, and escalation matrix
  • Secure communication procedures and SLA/OLA handoff alignment
  • Support pre-engagement risk assessments and operational readiness reviews.

Required Skills & Qualifications:

1.    Education:

·      Bachelor's Degree in Cybersecurity, Computer Science, Information Systems, or related field.

·      Master's Degree is a plus.

2.    Certifications (Preferred):

·      Microsoft Certified: Security Operations Analyst Associate

·      GIAC (GCIA, GCIH, GCFA, GNFA)

·      CompTIA CySA+, CASP+, or equivalent

·      MITRE ATT&CK Defender (MAD) certification is advantageous

3.    Technical Skills:

·      Expert in SIEM technologies (Microsoft Sentinel preferred), KQL, log analysis, and data correlation.

·      Hands-on experience with EDR tools (Defender for Endpoint, CrowdStrike, etc.).

·      Strong knowledge of MITRE ATT&CK, NIST IR lifecycle, and threat modeling.

·      Familiarity with threat intel platforms (MISP, Anomaly, Recorded Future).

·      Understanding of cloud security (Azure, M365, hybrid environments).

4.    Soft Skills:

·      Strong presentation and documentation skills, especially for executive and customer audiences.

·      Proven ability to lead and manage cross-functional engagements (internal & external).

·      Analytical mindset with an investigative approach to threat detection.

·      Ability to work independently in high-pressure and time-sensitive environments.

·      Proven English communication skills supported by professional certifications such as IELTS, TOEIC, or BEC.

·      Ability to write technical and executive-level documentation in English, including reports, presentations, and incident summaries.

Experience:

· years of experience in cybersecurity operations, with at least 2 years in a Level 2 or Level 3 SOC role.

·      Experience in delivering threat hunts, writing detection content, and handling major security incidents.

·      Prior MSSP experience or customer-facing security role is a significant advantage.


  • L3 SOC Analyst

    4 days ago


    Greater Noida, Uttar Pradesh, India Simran Consultant Full time ₹ 40,00,000 - ₹ 1,20,00,000 per year

    L3 SOC AnalystLeads major security incidents (P1/P2) end-to-endBuilds use cases using MITRE ATT&CK framework Develops SOAR automation playbooks for faster .Mentors L1 & L2 analysts and reviews their investigations

  • SOC Analyst

    1 week ago


    Noida, Uttar Pradesh, India AML RightSource Full time ₹ 6,00,000 - ₹ 18,00,000 per year

    Job Description:AML RightSource is a leading provider of anti-money laundering (AML) and financial crimescompliance solutions. Our team of experts provides our clients with the highest quality ofservice, while ensuring compliance with regulatory requirements. We are currently seeking aSenior SOC Analyst to join our team.Responsibilities:• Monitor and...

  • Soc Analyst L3

    4 days ago


    Greater Noida, Uttar Pradesh, India Infinity Exists Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Lead full lifecycle of P1/P2 incidents across customer environmentsDevelop complex detection logic/use cases for evolving threatsBuild detection artifacts from telemetryPerform timeline analysis, file carving, binary inspection and log correlation Required Candidate profile4-12exp.This role is also responsible for refining SOC processes andensuring...

  • Soc Analyst

    4 days ago


    Noida, Uttar Pradesh, India Net Connect Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    About the RoleAs a SOC AnalystatNCG, you will play a pivotal role in safeguarding our digital assets and ensuring the integrity of our information systems. Your expertise will directly contribute to the success of our organization by proactively identifying, analyzing, and responding to security incidents. You will be part of a collaborative team of 15...

  • Senior Soc Analyst

    4 days ago


    Noida, Uttar Pradesh, India Net Connect Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    About the RoleAs a SOC Analyst at NCG, you will play a pivotal role in safeguarding our organization against evolving cyber threats. Your expertise will directly contribute to the security posture of our company. You will work closely with cross-functional teams to foster a culture of security awareness and collaborate in a dynamic Security Operations Center...


  • Noida, Uttar Pradesh, India Sanganan IT Solutions Pvt Ltd. Full time ₹ 8,00,000 - ₹ 18,00,000 per year

    WORK FROM NOIDA OFFICE, PLEASE DON'T APPLY IF YOU ARE LOOKING FOR HYBRID OR WORK FROM HOMEDepartment:Managed Services & Support & Security Operations Center (SOC)Job Type:Full-TimeReports To:SOC Team Lead / Head of Cybersecurity ServicesJob Overview:We are seeking a technically skilled and detail-orientedSOC Content Detection Engineerto lead the development,...

  • SOC Analyst L1

    4 days ago


    Noida, Uttar Pradesh, India Sanganan IT Solutions Pvt Ltd. Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Job Title:Level 1 Security Operations Center (SOC) AnalystJob Type: Full TimeJob Location:WORK FROM NOIDA OFFICE, PLEASE DON'T APPLY IF YOU ARE LOOKING FOR HYBRID OR WORK FROM HOMEShort notice period or immediate joiners are preferred.Job Overview:As a Level 1 SOC Analyst, you will be at the forefront of the organization's cybersecurity defenses,...

  • SOC Manager

    4 days ago


    Noida, Uttar Pradesh, India Paytm Services Private Limited Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    SOC Manager-Paytm MoneyThe SOC Manager will be responsible for overseeing the security operations center, ensuring the protection of Paytm Money's digital assets. They will lead a team of security analysts, manage incident response, and implement security measures to safeguard the organization's information systems


  • Noida, Uttar Pradesh, India Net Connect Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    About the RoleAs a Senior EDR SOC Analyst at NCG , you will play a pivotal role in safeguarding our organization against evolving cyber threats. Your expertise in endpoint detection and response (EDR) will directly contribute to our mission of providing secure and resilient digital environments for our clients. By leading complex investigations and...

  • soc analyst

    8 hours ago


    Noida, Uttar Pradesh, India Ontinue Full time ₹ 12,00,000 - ₹ 24,00,000 per year

    As a leading provider of AI-powered extended managed detection and response (MXDR) services, Ontinue is on a mission to be the most trusted, 24/7, always-on security partner that empowers customers to embrace the future by using AI to operate more strategically, at scale, and with less risk. We believe that the combination of AI and human expertise is...