All jobs
AlifCloud IT Consulting Pvt. Ltd. logo

SOC Analyst

AlifCloud IT Consulting Pvt. Ltd. · Posted today

  • Pune Division, Maharashtra, India (On-site)
  • Full-time
  • 1-3 yrs

About the role

Title: SOC Analyst – L1

Location: Pune

Experience: 1–2Years

Employment Type: Full-Time

Shift: Rotational Shifts, including Night Shifts

About the Role

We are looking for a SOC Analyst – L1 to join our Security Operations Center team. The ideal candidate should have hands-on experience working with Microsoft Sentinel, be comfortable writing KQL queries, and have prior experience in an MSSP/SOC environment.

The candidate will be responsible for continuous security monitoring, initial alert investigation, incident triage, escalation, and supporting the incident response team.

Key Responsibilities

  • Monitor security alerts and events using Microsoft Sentinel and other security monitoring tools.
  • Perform L1 alert triage and investigate suspicious activities.
  • Analyze logs from endpoints, firewalls, network devices, cloud environments, identity systems, and other security sources.
  • Write and execute KQL (Kusto Query Language) queries for alert investigation, threat hunting, and log analysis.
  • Perform initial investigation of security incidents and determine severity, impact, and priority.
  • Identify false positives and perform appropriate alert closure with proper documentation.
  • Escalate confirmed or complex incidents to L2/L3 / Incident Response teams.
  • Have a basic understanding of Incident Response (IR) processes, including identification, containment, eradication, and recovery.
  • Follow SOC playbooks, escalation procedures, and incident-handling processes.
  • Maintain accurate investigation notes and incident documentation.
  • Work with multiple customer environments in an MSSP setup while maintaining SLA requirements.
  • Participate in continuous improvement of detection rules, use cases, and SOC processes.
  • Stay updated on common attack techniques, vulnerabilities, and threat intelligence.
  • Mandatory Skills & Experience
  • 1–3 years of experience in SOC / Cybersecurity Operations.
  • Hands-on experience with Microsoft Sentinel is mandatory.
  • Good understanding of KQL and ability to write queries for security investigations.
  • Previous experience working in an MSSP / Managed SOC environment is mandatory.
  • Experience handling and triaging security alerts/incidents.
  • Basic understanding of Incident Response and SOC processes.
  • Basic understanding of SIEM concepts and log analysis.
  • Understanding of common security threats such as phishing, malware, brute-force attacks, credential attacks, suspicious PowerShell activity, and unauthorized access.
  • Ability to analyze security events and correlate information from multiple log sources.
  • Willingness to work in rotational shifts, including night shifts, weekends, and public holidays.
  • Good communication and incident documentation skills.

Good to Have

  • Experience with Microsoft Defender XDR / Defender for Endpoint / Defender for Identity.
  • Knowledge of Azure and Microsoft Entra ID security.
  • Experience with EDR/XDR platforms.
  • Basic knowledge of network security, firewalls, IDS/IPS, VPN, DNS, and authentication protocols.
  • Knowledge of MITRE ATT&CK framework.
  • Experience creating or tuning Sentinel analytics rules and detection use cases.
  • Relevant certifications such as SC-200, Security+, CEH, or equivalent.
  • Candidate Profile

We are looking for someone who

  • Can independently perform L1 alert triage.
  • Is comfortable working with Microsoft Sentinel and KQL daily.
  • Understands how an MSSP/SOC operates across multiple customers.

Can differentiate between false positives and genuine security incidents.

Has a security-first mindset and strong analytical skills.

Is comfortable working under SLA-driven and shift-based SOC operations.

Is willing to learn and progress toward an L2 SOC / Incident Response role.

Important Requirement

Candidates without hands-on Microsoft Sentinel and KQL experience, or without prior MSSP/SOC experience, may not be considered.

Skills

Microsoft SentinelKQLSecurity monitoring tools