SOC Analyst — Security Operations
Full Job Description
ESSENTIAL JOB DUTIES
Monitor and manage the security alert queue continuously across shifts to ensure no alerts are missed, delayed, or improperly documented. Perform initial triage of incoming alerts by reviewing context, classifying severity, and determining disposition—escalating to L2 when necessary. Utilize documented playbooks and GreyMatter workflows to guide decisions, ensuring accurate documentation of findings, escalations, and handoffs.
Key Responsibilities:
- Conduct thorough alert triage using GreyMatter’s AI-assisted features, validating outputs before action.
- Review Microsoft Defender for Endpoint alerts, perform basic endpoint investigations, and classify severity using MDE criteria.
- Analyze Microsoft Sentinel incidents, run KQL queries, and support triage findings with log evidence.
- Develop familiarity with Zscaler and Netskope alert types, review web security events, and escalate high-complexity cases.
- Manage ServiceNow tickets for InfoSec/SOC issues, ensuring SLA compliance, documentation, and escalation for unresolved patterns.
- Triage user-reported phishing/suspicious emails using Mimecast/Abnormal.ai, classify threats, and document outcomes.
TECHNICAL SKILLS & EXPERIENCE
1+ years in SOC, IT operations, or security monitoring roles. Proficiency in Windows OS, networking fundamentals (TCP/IP, DNS, HTTP/S), and ServiceNow ITSM. Preferred: SIEM (Sentinel/Splunk), EDR (Defender for Endpoint), and phishing analysis tools.
EDUCATION & CERTIFICATIONS
Bachelor’s in Computer Science/Engineering or equivalent. Preferred: CompTIA Security+, Microsoft SC-900, or CySA+.
Company
Revantage Global Services India Private Limited
Revantage Global Services India Private Limited is a leading provider of enterprise-grade security and IT operations solutions, specializing in cybersecurity, threat detection, and risk management for...