Job Description : SOC Incident Response + Threat Intelligence / Threat Hunting (L3)
Position Title :L3 Security Analyst - SOC Incident Response, Threat Intelligence & Threat Hunting
Experience : 6-10+ years in Cyber Security Operations, Incident Response, Threat Intelligence, and Threat Hunting
Location : Flexible / Hybrid / Onsite
Role Summary :
We are looking for an experienced L3 SOC Security Analyst with strong expertise in Incident Response (IR), Threat Intelligence (TI), and proactive Threat Hunting. The candidate will act as a senior escalation point for high-severity security incidents, conduct advanced investigations, develop threat hunting hypotheses, and provide actionable intelligence to improve the organization's overall security posture. The role requires hands-on expertise across SIEM, EDR/XDR, network security monitoring, malware analysis, threat intelligence platforms, and cloud security monitoring.
Key Responsibilities :
1. Incident Response & Security Operations :
- Lead investigation and response activities for complex security incidents including :
1. Ransomware
2. Advanced Persistent Threats (APT)
3. Insider threats
4. Credential compromise
5. Web application attacks
6. Cloud security incidents
7. Data exfiltration
8. Lateral movement
9. Privilege escalation
- Perform advanced triage and root cause analysis using :
1. SIEM
2. EDR/XDR
3. Network telemetry
4. Threat intelligence feeds
5. Cloud logs
6. Endpoint forensics
- Handle L3 escalations from L1/L2 SOC analysts.
- Conduct incident containment, eradication, and recovery coordination.
- Develop and improve :
1. Incident response playbooks
2. Detection use cases
3. Correlation rules
4. SOC runbooks
5. Automation workflows
- Coordinate with infrastructure, cloud, application, and business teams during major incidents.
- Prepare executive and technical incident reports with actionable recommendations.
2. Threat Intelligence Responsibilities :
- Monitor and analyze cyber threat intelligence from :
1. Commercial TI platforms
2. Open-source intelligence (OSINT)
3. Government/CERT advisories
4. Dark web monitoring
5. Vendor threat reports
- Enrich alerts with Indicators of Compromise (IOCs), TTPs, malware intelligence, and adversary attribution.
- Map adversary activities to :
1. MITRE ATT&CK
2. Cyber Kill Chain
3. Diamond Model
- Analyze emerging threats, zero-days, ransomware campaigns, and targeted attack trends.
- Provide strategic and operational threat advisories to SOC and leadership teams.
- Create threat intelligence reports, executive summaries, and threat landscape assessments.
3. Threat Hunting Responsibilities :
- Conduct proactive threat hunting using hypothesis-driven methodologies.
- Hunt for :
1. Persistence mechanisms
2. Beaconing activity
3. Credential dumping
4. Living-off-the-land (LOLBins)
5. Command & Control (C2)
6. Suspicious PowerShell activity
7. Lateral movement
8. Cloud anomalies
- Use telemetry from :
1. SIEM
2. EDR/XDR
3. DNS
4. Proxy
5. Firewall
6. Identity systems
7. Cloud platforms
- Develop custom queries and analytics for detecting stealthy attacker behavior.
- Identify detection gaps and recommend logging improvements.
- Convert hunt findings into production-grade detection use cases.
Required Technical Skills :
1. SIEM & Security Monitoring :
- IBM QRadar
- Microsoft Sentinel
- Splunk Enterprise Security
- ArcSight
- LogRhythm
2. EDR/XDR Technologies :
- CrowdStrike Falcon
- Microsoft Defender for Endpoint
- SentinelOne
- Palo Alto Cortex XDR
3. Threat Intelligence Platforms :
- Recorded Future
- Anomali ThreatStream
- MISP
- ThreatConnect
4. Cloud & Infrastructure Security :
- Amazon Web Services security monitoring
- Microsoft Azure security services
- Google Cloud Platform logging and detections
- Identity security and IAM monitoring
- Container/Kubernetes security basics
5. Investigation & Analysis Skills :
- Malware triage and behavioural analysis
- Windows/Linux forensic analysis
- Memory and disk artifact analysis
- Packet analysis using Wireshark
- Threat actor TTP analysis
- IOC enrichment and validation
6. Scripting & Automation :
- Python
- PowerShell
- KQL
- SPL
- Regex
- API integrations
- SOAR automation
Desired Certifications :
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensic Analyst (GCFA)
- GIAC Certified Intrusion Analyst (GCIA)
- Certified Threat Intelligence Analyst (CTIA)
- EC-Council Certified Ethical Hacker (CEH)
- ISC2 CISSP
- Security vendor certifications
Key Competencies :
- Strong analytical and investigative mindset
- Excellent communication and stakeholder management
- Ability to work during high-pressure incidents
- Deep understanding of attacker methodologies
- Strong documentation and reporting capability
- Mentoring and guidance for junior analysts
- Ability to independently lead investigations
Preferred Exposure :
- MDR/MSSP environment
- Healthcare / BFSI / Critical infrastructure domains
- Threat hunting frameworks
- Purple team exercises
- MITRE ATT&CK-based detection engineering
- SOAR platforms and automation
- Cloud-native SOC operations
Typical Deliverables :
- Incident investigation reports / RCA
- Threat intelligence advisories
- Hunting reports and findings
- Detection use cases
- IOC/TTP repositories / MITRE
- Executive risk summaries
- Threat landscape assessments
- SOC maturity improvement recommendations
- Presentation skills
- Communication skills
Happiest Minds Technologies - Technical Lead - SOC Monitoring • Bengaluru