Senior SOC Analyst
HCLTech
Job Description
We are seeking an experienced Senior SOC Analyst to operate side‑by‑side with our internal security team , providing advanced detection, investigation, and response capabilities. The ideal candidate is a critical thinker , highly hands‑on, and immediately effective within a mature Microsoft‑centric security environment. This role requires deep technical expertise across SIEM, EDR, email security, web security , and cloud platforms , with a strong emphasis on log analysis and incident investigation at scale .
Key Responsibilities Monitor, investigate, and respond to security alerts and incidents across enterprise and cloud environments Perform advanced log analysis to identify threats, root causes, and attack paths Triage and escalate incidents appropriately, working collaboratively with internal security and IT teams Tune and optimize detection rules, alerts, and use cases to reduce false positives and improve signal quality Conduct threat hunting activities across endpoint, network, cloud, and identity data sources Support incident response activities, including containment, remediation, and post‑incident analysis Document investigations, findings, and recommendations clearly and concisely Act as a senior technical escalation point within SOC operations Required Technical Skills & Experience Microsoft Security Stack (very strong proficiency required): Microsoft Defender (Endpoint, Identity, Cloud) Microsoft Sentinel (SIEM, KQL, analytics rules, workbooks) Email & Web Security: Proofpoint (Email Protection) Zscaler (Web / Cloud Security) Security Operations Expertise Expert experience investigating alerts from: SIEM EDR / XDR Email Security Gateways Web Security / Secure Web Gateways Strong understanding of attack techniques , indicators of compromise, and MITRE ATT&CK concepts Proven ability to analyze large volumes of diverse security telemetry Cloud, Infrastructure & Networking Experience operating in large, multi‑cloud environments (Azure required; AWS/GCP a strong plus) Solid knowledge of: Cloud-native logging and security controls Operating systems (Windows and Linux) Network protocols, traffic analysis, and authentication flows Scripting & Query Languages Working knowledge (hands‑on preferred) of: KQL (required) PowerShell Bash Lambda (or equivalent serverless scripting concepts) #J-18808-Ljbffr