Padmi
Saviynt logo
Saviynt

Identity Governance & Administration (IGA) · Privileged Access Management (PAM)

SOC Analyst II

India · HybridPosted 3 months ago
SecurityMid-level
Apply at Saviynt

Opens the source posting on jobs.lever.co

Source description

About the role

View original

Incident Triage & Investigation ● Serve as the primary escalation point for alerts triaged by L1 analysts. ● Conduct detailed analysis of security alerts from a wide range of sources (SIEM, EDR, CSPM, Cloud-native tools) to validate threats and determine their scope. ● Investigate security incidents in our enterprise and cloud environments (AWS, Azure, GCP), correlating data to build a complete picture of attacker activity. ● Perform deep-dive analysis of logs, kubernetes containers, and endpoint data to identify indicators of compromise (IOCs). Incident Response & Automation ● Execute and tune automated response playbooks using our SOAR platform for common security incidents. ● Perform timely incident response actions, such as isolating compromised hosts, blocking malicious IPs/domains, and disabling compromised accounts. ● Utilize and modify existing scripts (primarily Python) to assist with automated evidence collection and enrichment. ● Document all investigation steps, findings, and containment actions in our incident management system.

Threat Hunting & Cloud Monitoring ● Participate in hypothesis based threat hunting campaigns based on new threat intelligence or hypotheses developed by senior analysts. ● Actively monitor and analyze security logs from cloud-native tools (e.g., AWS GuardDuty, CloudTrail,Cloudflare, Azure,etc.) and kubernetes containers. ● Assist in tuning detection rules and identifying false positives to help improve the fidelity of our security alerts. Continuous Improvement & Collaboration ● Escalate complex, high-severity, or unresolved incidents to L3 Analysts and the Incident Response team with detailed handover notes. ● Contribute to the refinement of SOC documentation, including Standard Operating Procedures (SOPs) and investigation runbooks. ● Provide guidance and mentorship to L1 analysts on triage techniques and alert analysis.

More at Saviynt

Related open roles

View all roles