We are seeking an experienced and highly analytical Information Security Analyst. This role is responsible for monitoring, validating, investigating, and clarifying security events and incidents across the organization. The analyst will work extensively with the SOC team to improve detection coverage, tune and create correlation rules, enhance alert quality, and strengthen incident handling processes. The role will also be expected to bring hands-on experience and practical recommendations to support the implementation of SOAR capabilities, including automation use cases, playbooks, enrichment workflows, and response processes. The role requires strong hands-on investigation skills, solid understanding of digital forensics, and the ability to trace suspicious activity across endpoints, networks, cloud services, identity systems, and business applications. The analyst will work closely with SecOps engineers, security architects, network security experts, R&D, IT, and other stakeholders to ensure threats are detected, investigated, and handled effectively.
Key Responsibilities
Advanced SOC Monitoring & Event Analysis
Monitor security events, alerts, logs, and telemetry across SIEM, XDR/EDR, identity, network, cloud, endpoint, email, and other enterprise security platforms.
Perform advanced investigation and triage of security alerts, validate incidents, reduce false positives, and determine severity, scope, business impact, and required response actions.
Analyze suspicious activities, attack indicators, anomalies, and behavioral patterns to identify potential threats and clarify whether events represent real security incidents.
Conduct detailed investigations using existing security tools and data sources, including logs, endpoint telemetry, network traffic, identity events, email traces, cloud activity, and threat intelligence.
Escalate confirmed incidents, recommend containment and remediation steps, and support incident response activities in collaboration with SecOps engineers and relevant technical teams.
Document investigation findings, evidence, timelines, root cause, affected assets, response actions, and lessons learned in a clear and structured manner.
Play a key role in maintaining visibility into suspicious activities and ensuring the company can detect, trace, investigate, and respond to security incidents effectively.
SIEM, Automation & Detection Engineering
Improve the SIEM platform by tuning alerts, creating and maintaining correlation rules, enhancing use cases, improving log source coverage, and increasing detection accuracy.
Design, recommend, and implement detection improvements based on incidents, threat intelligence, attack techniques, gaps in visibility, and operational lessons learned.
Contribute experience and practical guidance toward the implementation of SOAR capabilities, including playbook design, automation use cases, alert enrichment, case management, and response workflows.
Lead deep-dive investigations of confirmed or suspected incidents, including endpoint, network, identity, cloud, and application-related security events.
Apply digital forensics knowledge to preserve and analyze evidence, reconstruct attack timelines, understand attacker behavior, and support root-cause analysis.
Perform threat hunting activities to proactively identify suspicious behavior, weak detection areas, persistence mechanisms, lateral movement, privilege misuse, and data exposure indicators.
Work with SecOps engineers, security architects, network security experts, IT, R&D, cloud, and application teams to validate findings and coordinate containment, remediation, and control improvements.
Translate investigation outcomes into improved detection logic, response procedures, playbooks, dashboards, and security monitoring coverage.
Automation, Improvement & Collaboration
Use and improve existing security tools, while proposing practical ideas, enhancements, new detection use cases, and automation opportunities to improve SOC effectiveness.
Collaborate with SecOps and security architecture teams on new tool implementations, onboarding of log sources, integration design, alert enrichment, response automation, and future SOAR platform planning.
Continuously improve detection and handling processes by measuring alert quality, investigation efficiency, coverage gaps, incident trends, and lessons learned from real events.
Qualifications
Experience:
5+ years of hands-on experience in SOC operations, incident investigation, security monitoring, threat detection, SIEM operations, security automation, digital forensics, or enterprise security operations.
Proven experience working as an advanced SOC analyst, Tier 2/Tier 3 analyst, incident responder, detection analyst, or similar role in complex enterprise environments.
Deep technical knowledge of SIEM, XDR/EDR, log analysis, endpoint telemetry, identity security, network security, cloud security, email security, threat intelligence, security automation, and incident response processes.
Strong experience analyzing logs, alerts, events, and telemetry from multiple sources to validate incidents, identify attack patterns, and determine appropriate response actions.
Hands-on experience with incident response, threat investigation, containment recommendations, root-cause analysis, attack timeline reconstruction, and post-incident improvement.
Solid understanding of digital forensics concepts, evidence handling, endpoint investigation, malware behavior, persistence techniques, lateral movement, and attacker tactics, techniques, and procedures.
Experience creating, tuning, and improving SIEM correlation rules, detection use cases, dashboards, alert logic, and monitoring coverage.
Experience with security automation, playbook design, alert enrichment, case management concepts, workflow improvement, and supporting or driving SOAR implementation initiatives.
Ability to write clear investigation summaries, incident reports, detection documentation, playbooks, runbooks, and operational recommendations.
Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.
Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together.
Applicants
are
advised to research the bonafides of the prospective employer independently. We do NOT
endorse any
requests for money payments and strictly advice against sharing personal or bank related
information. We
also recommend you visit Security Advice for more information. If you suspect any fraud
or
malpractice,
email us at abuse@talentmate.com.
You have successfully saved for this job. Please check
saved
jobs
list
Applied
You have successfully applied for this job. Please check
applied
jobs list
Do you want to share the
link?
Please click any of the below options to share the job
details.
Report this job
Success
Successfully updated
Success
Successfully updated
Thank you
Reported Successfully.
Copied
This job link has been copied to clipboard!
Apply Job
Upload your Profile Picture
Accepted Formats: jpg, png
Upto 2MB in size
Your application for Information Security Analyst
has been successfully submitted!
To increase your chances of getting shortlisted, we recommend completing your profile.
Employers prioritize candidates with full profiles, and a completed profile could set you apart in the
selection process.
Why complete your profile?
Higher Visibility: Complete profiles are more likely to be viewed by employers.
Better Match: Showcase your skills and experience to improve your fit.
Stand Out: Highlight your full potential to make a stronger impression.
Complete your profile now to give your application the best chance!