Padmi

Lead - SOC Analyst

ChennaiPosted 2 months ago
CybersecuritySeniorFull Time; Regular
Apply at FRESHWORKS INC

Opens the source posting on shine.com

Source description

About the role

View original

Job Description Job Summary We are seeking a Lead SOC Engineer with strong expertise in SIEM administration, SOAR automation, and security monitoring across both enterprise and cloud environments. The role will focus on enhancing SOC capabilities, improving threat detection, automating response processes, and ensuring visibility across onpremises and cloud infrastructure. Key Responsibilities Administer, maintain, and optimize SIEM platforms (Splunk, Sentinel, QRadar, etc.). Design and implement SOAR playbooks to automate security operations and incident response. Onboard and manage log sources from enterprise infrastructure, applications, and cloud environments. Develop and tune detection rules, correlation searches, dashboards, and alerts. Support incident investigations, threat hunting, and response activities. Integrate SIEM/SOAR with EDR, IAM, cloud security, email security, and threat intelligence platforms. Collaborate with infrastructure, cloud, and security teams to improve monitoring coverage and security posture. Mentor SOC analysts and drive continuous improvement initiatives. Qualifications 610 years of cybersecurity experience with SOC Engineering/Security Operations focus. Minimum 3+ years of handson SIEM administration experience. Minimum 2+ years of SOAR implementation and automation experience. Strong experience managing security monitoring for both: Enterprise environments (Windows, Linux, Active Directory, Network Security, Endpoint Security) Cloud environments (Azure, AWS, and/or GCP) Experience in onboarding and correlating logs from cloudnative security services and enterprise security tools. Strong understanding of incident response, threat hunting, and detection engineering. Experience with Python, PowerShell, APIs, and automation scripting. Good knowledge of MITRE ATT&CK framework and modern threat detection methodologies. Preferred Certifications Microsoft SC-200 / SC-100 Splunk Certified Admin/Architect GCIH, GCED AWS or Azure Security certifications Additional Information At Freshworks, we have fostered an environment that enables everyone to find their true potential, purpose, and passion, welcoming colleagues of all backgrounds, genders, sexual orientations, religions, and ethnicities. We are committed to providing equal opportunity and believe that diversity in the workplace creates a more vibrant, richer environment that boosts the goals of our employees, communities, and business. Fresh vision. Real impact. Come build it with us. Job Description Job Summary We are seeking a Lead SOC Engineer with strong expertise in SIEM administration, SOAR automation, and security monitoring across both enterprise and cloud environments. The role will focus on enhancing SOC capabilities, improving threat detection, automating response processes, and ensuring visibility across onpremises and cloud infrastructure. Key Responsibilities Administer, maintain, and optimize SIEM platforms (Splunk, Sentinel, QRadar, etc.). Design and implement SOAR playbooks to automate security operations and incident response. Onboard and manage log sources from enterprise infrastructure, applications, and cloud environments. Develop and tune detection rules, correlation searches, dashboards, and alerts. Support incident investigations, threat hunting, and response activities. Integrate SIEM/SOAR with EDR, IAM, cloud security, email security, and threat intelligence platforms. Collaborate with infrastructure, cloud, and security teams to improve monitoring coverage and security posture. Mentor SOC analysts and drive continuous improvement initiatives. Qualifications 610 years of cybersecurity experience with SOC Engineering/Security Operations focus. Minimum 3+ years of handson SIEM administration experience. Minimum 2+ years of SOAR implementation and automation experience. Strong experience managing security monitoring for both: Enterprise environments (Windows, Linux, Active Directory, Network Security, Endpoint Security) Cloud environments (Azure, AWS, and/or GCP) Experience in onboarding and correlating logs from cloudnative security services and enterprise security tools. Strong understanding of incident response, threat hunting, and detection engineering. Experience with Python, PowerShell, APIs, and automation scripting. Good knowledge of MITRE ATT&CK framework and modern threat detection methodologies. Preferred Certifications Microsoft SC-200 / SC-100 Splunk Certified Admin/Architect GCIH, GCED AWS or Azure Security certifications Additional Information At Freshworks, we have fostered an environment that enables everyone to find their true potential, purpose, and passion, welcoming colleagues of all backgrounds, genders, sexual orientations, religions, and ethnicities. We are committed to providing equal opportunity and believe that diversity in the workplace creates a more vibrant, richer environment that boosts the goals of our employees, com

One address, no account. We’ll tell you when matching roles go live.

More at FRESHWORKS INC

Related open roles

View all roles