Padmi

Security Analyst L1 (CrowdStrike Specialist)

BangalorePosted 1 month ago
CybersecurityJuniorFull Time; Regular
Apply at Cyber Sainik

Opens the source posting on shine.com

Source description

About the role

View original

We are looking for an experienced Security Analyst with a minimum of 2 years of hands-on experience and mandatory CrowdStrike certification to join our Security Operations Center (SOC) team. In this role, you will be a key part of our 24x7x365 white-glove SOC, responsible for monitoring, advanced alert triage, threat hunting, and incident mitigation across our next-generation security platform. You will leverage the CrowdStrike Falcon ecosystem alongside integrated email and network telemetry to defend our clients' environments against sophisticated cyber threats. Key Responsibilities-Security Monitoring & Platform Management Monitor and analyze security alerts and logs utilizing the CrowdStrike Managed Next-Gen SIEM Complete platform. Oversee endpoint, cloud, and identity alerts using CrowdStrike Falcon Complete , Falcon Cloud & Identity , and Exposure Management + ONUM . Monitor integrated telemetry streams, including Abnormal Email Security and Palo Alto Network Ingestion . Follow and optimize defined SOC runbooks and escalation procedures. Advanced Alert Triage & Investigation Perform deep-dive triage of complex security alerts to identify true positives and zero-day threats. Review raw logs, behavioral indicators, and threat intelligence to isolate malicious activity from false positives. Conduct proactive threat hunting within the Falcon platform to identify hidden vectors of compromise. Collect forensic details and escalate critical, validated incidents to senior incident response teams. Incident Response & Containment Actions Execute rapid response actions directly through the Falcon console, including network containment/endpoint isolation. Mitigate identity risks by blocking malicious IPs/domains and performing account password resets or session revocations according to SOPs. Collaborate closely with engineering and senior analysts during active, high-severity incidents. Log Analysis & Threat Modeling Query and filter massive datasets using modern log query languages to investigate anomalies. Map adversary behaviors and techniques against the MITRE ATT&CK framework to improve detection capabilities. Documentation & Shift Collaboration Create, update, and manage incident tickets with meticulous timelines and technical notes. Ensure seamless communication and detailed technical handovers during 24x7 shift rotations. Required Skills & Qualifications Experience Minimum 2+ years of professional experience working within a fast-paced SOC environment. Certifications (Mandatory) Must hold at least one active CrowdStrike Certification (e.g., CrowdStrike Certified Falcon Analyst [CCFA], CrowdStrike Certified Falcon Administrator [CCFR], or CrowdStrike Certified Falcon Hunter [CCFH]). Technical Skills & Knowledge Strong technical proficiency in the CrowdStrike Falcon platform (EDR/XDR, Identity Protection, Cloud Security). Solid understanding of network security concepts, log analysis, and email security fundamentals (experience with Palo Alto Networks and Abnormal Security is a plus). Proven understanding of modern attack vectors, malware behavior, and standard incident response lifecycles. Employment Type Full Time Permanent (Shifts required for 24x7x365 coverage) We are looking for an experienced Security Analyst with a minimum of 2 years of hands-on experience and mandatory CrowdStrike certification to join our Security Operations Center (SOC) team. In this role, you will be a key part of our 24x7x365 white-glove SOC, responsible for monitoring, advanced alert triage, threat hunting, and incident mitigation across our next-generation security platform. You will leverage the CrowdStrike Falcon ecosystem alongside integrated email and network telemetry to defend our clients' environments against sophisticated cyber threats. Key Responsibilities-Security Monitoring & Platform Management Monitor and analyze security alerts and logs utilizing the CrowdStrike Managed Next-Gen SIEM Complete platform. Oversee endpoint, cloud, and identity alerts using CrowdStrike Falcon Complete , Falcon Cloud & Identity , and Exposure Management + ONUM . Monitor integrated telemetry streams, including Abnormal Email Security and Palo Alto Network Ingestion . Follow and optimize defined SOC runbooks and escalation procedures. Advanced Alert Triage & Investigation Perform deep-dive triage of complex security alerts to identify true positives and zero-day threats. Review raw logs, behavioral indicators, and threat intelligence to isolate malicious activity from false positives. Conduct proactive threat hunting within the Falcon platform to identify hidden vectors of compromise. Collect forensic details and escalate critical, validated incidents to senior incident response teams. Incident Response & Containment Actions Execute rapid response actions directly through the Falcon console, including network containment/endpoint isolation. Mitigate identity risks by blocking malicious IPs/domains and

One address, no account. We’ll tell you when matching roles go live.

More at Cyber Sainik

Related open roles

View all roles