Sun King logo
Sun KingPosted 1 month ago

Security Operations Center Analyst

RemoteIndia or New Delhi, Delhi, India

Full TimeMedium

Job Summary

Monitor, triage, and investigate security events across AWS, endpoint security platforms, Google Workspace, and identity providers. Review threat intelligence feeds, Indicators of Compromise, and MITRE ATT&CK data to validate detections and enrich investigations with OSINT. Correlate telemetry from SIEM, EDR, and cloud environments to build context for threat hunting and incident response. Design, develop, and optimize SIEM/SOAR detection rules, playbooks, and dashboards while onboarding new log sources. Lead end-to-end incident response activities, including containment, eradication, root cause analysis, and reporting. Administer security technologies, develop automation scripts using Python and PowerShell, and evaluate AI-assisted security workflows. Collaborate with Infrastructure, Cloud, and Engineering teams to implement controls and coordinate response activities.

Required Qualifications

  • 3–6 years of experience in Security Operations, including threat detection, incident response, threat hunting, and digital forensics across cloud and enterprise environments
  • Demonstrated experience managing high-severity security incidents and improving SOC capabilities through process improvements, automation, and measurable operational metrics
  • Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related discipline, or equivalent practical experience
  • Strong written and verbal communication skills, with the ability to collaborate effectively across technical and non-technical teams

Desired Qualifications

  • Professional security certifications such as OSCE, CRTP, SC-200, or equivalent
  • Experience building AI- or LLM-assisted SOC workflows for alert triage, investigation summarization, and multi-source threat correlation while validating AI-generated outputs for accuracy
  • Familiarity with AI security frameworks and threat models such as MITRE ATLAS and the OWASP Top 10 for LLM Applications
  • Proficiency in Python, PowerShell, Bash, and REST APIs to develop automation, detection content, playbooks, and security workflows
  • Experience integrating security technologies, managing log pipelines, and implementing automation that balances operational efficiency with appropriate human oversight
  • Strong interest in emerging threats, attacker techniques, and defensive strategies, with a commitment to continuous learning and professional development
  • Demonstrated ownership, problem-solving ability, and commitment to protecting organizational assets while enabling secure business operations

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce