Source description
About the role
Job Type: Full-time We are looking for an experienced Security Analyst with a minimum of 2 years of hands-on experience and mandatory CrowdStrike certification to join our Security Operations Center (SOC) team. In this role, you will be a key part of our 24x7x365 white-glove SOC, responsible for monitoring, advanced alert triage, threat hunting, and incident mitigation across our next-generation security will leverage the CrowdStrike Falcon ecosystem alongside integrated email and network telemetry to defend our clients' environments against sophisticated cyber Responsibilities- Security Monitoring & Platform ManagementMonitor and analyze security alerts and logs utilizing the CrowdStrike Managed Next-Gen SIEM Complete endpoint, cloud, and identity alerts using CrowdStrike Falcon Complete, Falcon Cloud & Identity, and Exposure Management + ONUM.Monitor integrated telemetry streams, including Abnormal Email Security and Palo Alto Network Ingestion.Follow and optimize defined SOC runbooks and escalation procedures.Advanced Alert Triage & InvestigationPerform deep-dive triage of complex security alerts to identify true positives and zero-day raw logs, behavioral indicators, and threat intelligence to isolate malicious activity from false positives.Conduct proactive threat hunting within the Falcon platform to identify hidden vectors of compromise.Collect forensic details and escalate critical, validated incidents to senior incident response teams.Incident Response & Containment ActionsExecute rapid response actions directly through the Falcon console, including network containment/endpoint identity risks by blocking malicious IPs/domains and performing account password resets or session revocations according to SOPs.Collaborate closely with engineering and senior analysts during active, high-severity incidents.Log Analysis & Threat ModelingQuery and filter massive datasets using modern log query languages to investigate anomalies.Map adversary behaviors and techniques against the MITRE ATT&CK; framework to improve detection capabilities.Documentation & Shift CollaborationCreate, update, and manage incident tickets with meticulous timelines and technical notes.Ensure seamless communication and detailed technical handovers during 24x7 shift Skills & QualificationsExperienceMinimum 2+ years of professional experience working within a rapid-paced SOC environment.Certifications (Mandatory)Must hold at least one active CrowdStrike Certification (e.g., CrowdStrike Certified Falcon Analyst [CCFA], CrowdStrike Certified Falcon Administrator [CCFR], or CrowdStrike Certified Falcon Hunter [CCFH]).Technical Skills & KnowledgeStrong technical proficiency in the CrowdStrike Falcon platform (EDR/XDR, Identity Protection, Cloud Security).Solid understanding of network security concepts, log analysis, and email security fundamentals (experience with Palo Alto Networks and Abnormal Security is a plus).Proven understanding of modern attack vectors, malware behavior, and standard incident response lifecycles.Employment TypeFull Time Permanent (Shifts required for 24x7x365 coverage) .
More at Cyber Sainik