Talent.com
Happiest Minds Technologies Limited
Happiest Minds Technologies - Technical Lead - SOC MonitoringHappiest Minds Technologies Limited • Bengaluru
Happiest Minds Technologies - Technical Lead - SOC Monitoring

Happiest Minds Technologies - Technical Lead - SOC Monitoring

Happiest Minds Technologies Limited • Bengaluru
18 days ago
Job description

Job Description : SOC Incident Response + Threat Intelligence / Threat Hunting (L3)

Position Title :L3 Security Analyst - SOC Incident Response, Threat Intelligence & Threat Hunting

Experience : 6-10+ years in Cyber Security Operations, Incident Response, Threat Intelligence, and Threat Hunting

Location : Flexible / Hybrid / Onsite

Role Summary :

We are looking for an experienced L3 SOC Security Analyst with strong expertise in Incident Response (IR), Threat Intelligence (TI), and proactive Threat Hunting. The candidate will act as a senior escalation point for high-severity security incidents, conduct advanced investigations, develop threat hunting hypotheses, and provide actionable intelligence to improve the organization's overall security posture. The role requires hands-on expertise across SIEM, EDR/XDR, network security monitoring, malware analysis, threat intelligence platforms, and cloud security monitoring.

Key Responsibilities :

1. Incident Response & Security Operations :

- Lead investigation and response activities for complex security incidents including :

1. Ransomware

2. Advanced Persistent Threats (APT)

3. Insider threats

4. Credential compromise

5. Web application attacks

6. Cloud security incidents

7. Data exfiltration

8. Lateral movement

9. Privilege escalation

- Perform advanced triage and root cause analysis using :

1. SIEM

2. EDR/XDR

3. Network telemetry

4. Threat intelligence feeds

5. Cloud logs

6. Endpoint forensics

- Handle L3 escalations from L1/L2 SOC analysts.

- Conduct incident containment, eradication, and recovery coordination.

- Develop and improve :

1. Incident response playbooks

2. Detection use cases

3. Correlation rules

4. SOC runbooks

5. Automation workflows

- Coordinate with infrastructure, cloud, application, and business teams during major incidents.

- Prepare executive and technical incident reports with actionable recommendations.

2. Threat Intelligence Responsibilities :

- Monitor and analyze cyber threat intelligence from :

1. Commercial TI platforms

2. Open-source intelligence (OSINT)

3. Government/CERT advisories

4. Dark web monitoring

5. Vendor threat reports

- Enrich alerts with Indicators of Compromise (IOCs), TTPs, malware intelligence, and adversary attribution.

- Map adversary activities to :

1. MITRE ATT&CK

2. Cyber Kill Chain

3. Diamond Model

- Analyze emerging threats, zero-days, ransomware campaigns, and targeted attack trends.

- Provide strategic and operational threat advisories to SOC and leadership teams.

- Create threat intelligence reports, executive summaries, and threat landscape assessments.

3. Threat Hunting Responsibilities :

- Conduct proactive threat hunting using hypothesis-driven methodologies.

- Hunt for :

1. Persistence mechanisms

2. Beaconing activity

3. Credential dumping

4. Living-off-the-land (LOLBins)

5. Command & Control (C2)

6. Suspicious PowerShell activity

7. Lateral movement

8. Cloud anomalies

- Use telemetry from :

1. SIEM

2. EDR/XDR

3. DNS

4. Proxy

5. Firewall

6. Identity systems

7. Cloud platforms

- Develop custom queries and analytics for detecting stealthy attacker behavior.

- Identify detection gaps and recommend logging improvements.

- Convert hunt findings into production-grade detection use cases.

Required Technical Skills :

1. SIEM & Security Monitoring :

- IBM QRadar

- Microsoft Sentinel

- Splunk Enterprise Security

- ArcSight

- LogRhythm

2. EDR/XDR Technologies :

- CrowdStrike Falcon

- Microsoft Defender for Endpoint

- SentinelOne

- Palo Alto Cortex XDR

3. Threat Intelligence Platforms :

- Recorded Future

- Anomali ThreatStream

- MISP

- ThreatConnect

4. Cloud & Infrastructure Security :

- Amazon Web Services security monitoring

- Microsoft Azure security services

- Google Cloud Platform logging and detections

- Identity security and IAM monitoring

- Container/Kubernetes security basics

5. Investigation & Analysis Skills :

- Malware triage and behavioural analysis

- Windows/Linux forensic analysis

- Memory and disk artifact analysis

- Packet analysis using Wireshark

- Threat actor TTP analysis

- IOC enrichment and validation

6. Scripting & Automation :

- Python

- PowerShell

- KQL

- SPL

- Regex

- API integrations

- SOAR automation

Desired Certifications :

- GIAC Certified Incident Handler (GCIH)

- GIAC Certified Forensic Analyst (GCFA)

- GIAC Certified Intrusion Analyst (GCIA)

- Certified Threat Intelligence Analyst (CTIA)

- EC-Council Certified Ethical Hacker (CEH)

- ISC2 CISSP

- Security vendor certifications

Key Competencies :

- Strong analytical and investigative mindset

- Excellent communication and stakeholder management

- Ability to work during high-pressure incidents

- Deep understanding of attacker methodologies

- Strong documentation and reporting capability

- Mentoring and guidance for junior analysts

- Ability to independently lead investigations

Preferred Exposure :

- MDR/MSSP environment

- Healthcare / BFSI / Critical infrastructure domains

- Threat hunting frameworks

- Purple team exercises

- MITRE ATT&CK-based detection engineering

- SOAR platforms and automation

- Cloud-native SOC operations

Typical Deliverables :

- Incident investigation reports / RCA

- Threat intelligence advisories

- Hunting reports and findings

- Detection use cases

- IOC/TTP repositories / MITRE

- Executive risk summaries

- Threat landscape assessments

- SOC maturity improvement recommendations

- Presentation skills

- Communication skills

(ref:hirist.tech)
Create a job alert for this search

Happiest Minds Technologies - Technical Lead - SOC Monitoring • Bengaluru