SOC Analyst at Innspark Solutions · Delhi, Gurugram, Noida, Ghaziabad, Faridabad · 1 - 3 years · ₹4L - ₹8L / yr · Profitable · Posted 11 Dec 2024

Role: SOC Analyst
Job Type: Full Time, Permanent
Location: Onsite – Delhi
Experience Required: 1-3 Yrs
Skills Required:
1) Working knowledge across various security appliances (e.g., Firewall, WAF, Web Security Appliance, Email Security Appliance, Antivirus).
2) Experience with SOC Operations tools like SIEM, NDR, EDR, UEBA, SOAR, etc.
3) Strong analytical and problem-solving skills, with a deep understanding of cybersecurity principles, attack vectors, and threat intelligence.
4) Knowledge of network protocols, security technologies, and the ability to analyze and interpret security logs and events to identify potential threats.
5) Scripting skills (e.g., Python, Bash, PowerShell) for automation and analysis purposes.
6) Skilled in evaluating and integrating inputs from people, processes, and technologies to identify effective solutions.
7) Demonstrate a thorough understanding of the interdependencies between these elements and leverages this knowledge to develop comprehensive, efficient, and sustainable problem-solving strategies.
8) Excellent communication skills to articulate complex technical concepts to non-technical stakeholders and collaborate effectively with team members.
9) Ability to prioritize and manage multiple tasks in a dynamic environment.
10) Willingness to stay updated with the latest cybersecurity trends and technologies.
Job Responsibilities:
1) Continuously monitor and Analyze security alerts and logs to identify potential incidents. Analyze network traffic patterns to detect anomalies and identify potential security breaches.
2) Implement correlation rules and create playbooks as per requirements. Continuously update and suggest new rules and playbooks based on the latest attack vectors and insights from public articles and cybersecurity reports.
3) Use security compliance and scanning solutions to conduct assessments and validate the effectiveness of security controls and policies. Suggest improvements to enhance the overall security posture.
4) Utilize deception security solutions to deceive and detect potential attackers within the network.
5) Leverage deep expertise in networking, system architecture, operating systems, virtual machines (VMs), servers, and applications to enhance cybersecurity operations.
6) Work effectively with cross-functional teams to implement and maintain robust security measures. Conduct thorough forensic analysis of security incidents to determine root causes and impact.
7) Assist with all phases of incident response. Develop and refine incident response strategies and procedures to address emerging cyber threats.
8) Perform digital forensics to understand attack vectors and impact. Swiftly respond to and mitigate security threats, ensuring the integrity and security of organizational systems and data.
9) Professionally communicate and report technical findings, security incidents, and mitigation recommendations to clients.
About Company
Innspark is the fastest-growing Deep-tech Solutions company that provides next-generation products and services in Cybersecurity and Telematics. The Cybersecurity segment provides out-of-the-box solutions to detect and respond to sophisticated cyber incidents, threats, and attacks. The solutions are powered by advanced Threat Intelligence, Machine Learning, and Artificial Intelligence that provides deep visibility of the enterprise’s security.
We have developed and implemented solutions for a wide range of customers with highly complex environments including Government Organizations, Banks & Financial institutes, PSU, Healthcare Providers, Private Enterprises.
Website: https://innspark.in/

Similar jobs (8)
This role will be permanent with NAM info and deploy to client location Chennai.
Work Mode: WORK FROM OFFICE
Offer salary can offer on a decent hike
Role Descriptions:
Exp Range: 6-10 years
Primary Competency : Terraform, Hashi Sentinel (IaC/PaC), Kubernetes (GKE/EKS)
City Locations: Bengaluru or Chennai
Key Responsibilities*
Experience Required: 6-10
Role Descriptions:
Security Monitoring & Incident Response
Investigate and analyze security alerts escalated by L1 SOC analysts.
Perform triage, containment, eradication, and recovery activities for security incidents.
1. Perform in-depth analysis of security alerts escalated from L1
2. Investigate suspicious activities using SIEM, EDR, and threat intelligence tools
3. Correlate events across multiple log sources (firewalls, endpoints, IAM, cloud logs)
4. Validate true positives and recommend reducing false positives
5. Lead triage and response for medium to high severity incidents
6. Coordinate with IT, network, and application teams during incidents and support deep investigations when required
7. Conduct proactive threat hunting based on TTPs (e.g., MITRE ATT&CK)
8. Fine-tuning and optimize SIEM use cases to reduce false positives
9. Develop new correlation rules and detection logic
10. Document incidents, findings, and response actions
11. Prepare weekly , monthly reports for SOC leadership and stakeholders
Desire candidate
- Candidate should have valid PF.
Cyber Toddler is inviting applications for its 6-week Cybersecurity Operations, SOC & Threat Intelligence Internship — a weekend-only practical program designed for students, fresh graduates and early-career cybersecurity professionals.
The internship focuses on the skills used across modern security operations, including SOC monitoring, SIEM and log analysis, threat intelligence, incident response, threat hunting and security detection.
Rather than focusing only on theoretical learning, selected interns will work through simulated security incidents, investigate logs and indicators, analyze threats, document findings and complete a final cybersecurity investigation project.
What you will work on:
- SOC operations and security monitoring
- SIEM concepts and log analysis
- Security alert triage
- Threat intelligence and IOC investigation
- Phishing and suspicious activity analysis
- Incident response
- MITRE ATT&CK
- Threat hunting
- Detection engineering fundamentals
- Security investigation and reporting
- Cybersecurity documentation
- End-to-end SOC investigation
Duration: 6 weeks
Mode: Remote
Schedule: Weekends
Commitment: Approximately 4–5 hours per week
Cohort: Limited seats
A Senior Cybersecurity Engineer is responsible for safeguarding an organization’s IT infrastructure, applications, and data against cyber threats. With 5–10 years of experience, the role demands expertise in designing, implementing, and managing advanced security solutions, conducting risk assessments, and responding to incidents. Senior Engineers also mentor junior staff and contribute to strategic security planning.
Key Responsibilities
- Design, implement, and manage enterprise-level security solutions (firewalls, IDS/IPS, SIEM, endpoint protection).
- Conduct vulnerability assessments, penetration testing, and risk analysis.
- Monitor and respond to security incidents, ensuring timely resolution and documentation.
- Develop and enforce security policies, standards, and compliance frameworks (ISO 27001, NIST, GDPR).
- Collaborate with IT and business teams to integrate security into system architecture and processes.
- Lead incident response drills and disaster recovery planning.
- Provide guidance and mentorship to junior cybersecurity staff.
- Stay updated on emerging threats, tools, and technologies.
Qualifications
- Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
- 5–10 years of proven experience in cybersecurity engineering or related roles.
- Strong knowledge of network security, cloud security (AWS, Azure, GCP), and endpoint protection.
- Hands-on experience with SIEM tools (Splunk, QRadar, ArcSight), firewalls, and intrusion detection/prevention systems.
- Certifications such as CISSP, CISM, CEH, or OSCP are highly desirable.
Skills
- Advanced problem-solving and analytical skills.
- Strong communication and leadership abilities.
- Ability to manage complex projects and handle escalations effectively.
- Proactive mindset with adaptability to evolving cyber threats.
Job Summary:
We are looking for an experienced OpenText ArcSight SIEM / SOAR / UBA L2-L3 Engineer to manage and support security platforms in SOC/MSSP environment. The role involves day-to-day administration, troubleshooting, configuration and optimization of ArcSight platforms.
Key Responsibilities
- Administer and monitor OpenText ArcSight ESM/SIEM, SmartConnectors, SOAR and UBA/ArcSight Intelligence.
- Manage SIEM rules, filters, Active Lists, dashboards, reports and correlation use cases.
- Monitor EPS, event flow, connector health, system performance and log ingestion.
- Troubleshoot event collection, parsing, correlation and integration issues.
- Configure and troubleshoot ArcSight SmartConnectors and log sources.
- Manage and troubleshoot SOAR playbooks, integrations and automated workflows.
- Support UBA/Intelligence data ingestion, analytics and integration with SIEM.
- Perform L2/L3 troubleshooting, RCA and resolution of platform-related incidents.
- Support upgrades, patches, configuration changes and platform optimization.
- Coordinate with SOC, infrastructure, customer and OEM/OpenText support teams.
- Maintain technical documentation, incident records and RCA reports.
Required Skills
- 3–6 years of hands-on experience with OpenText ArcSight SIEM/ESM.
- Strong experience in ArcSight administration and troubleshooting.
- Hands-on experience with SmartConnectors, EPS, correlation rules, Active Lists and event flow.
- Working experience with ArcSight SOAR and UBA/ArcSight Intelligence.
- Good knowledge of Linux/Unix and networking fundamentals.
- Understanding of Syslog, CEF, TCP/IP, SSL/TLS and REST APIs.
- Strong analytical, troubleshooting and problem-solving skills.
- Experience in SOC/MSSP or managed security services environment preferred.
- OpenText/ArcSight certification will be an added advantage.
Candidate Profile
The candidate should be hands-on, technically strong and capable of independently handling L2/L3 production issues, platform administration, troubleshooting and escalations in a security operations environment.
We are looking for a Cybersecurity Engineer to protect our systems, applications and data. You will find vulnerabilities, monitor threats and strengthen our overall security posture.
Responsibilities
- Run vulnerability assessments and penetration tests (VAPT) on web apps, APIs and networks
- Monitor and respond to security events using SIEM tools as part of SOC operations
- Test application security using Burp Suite and similar tools
- Support ISO 27001 compliance, audits and security policies
- Harden network infrastructure, firewalls and access controls
- Document findings and track fixes with engineering teams
Requirements
- 1+ years of experience in VAPT, SOC or security engineering
- Hands-on experience with Burp Suite and SIEM tools
- Knowledge of the OWASP Top 10 and network security fundamentals
- Exposure to ISO 27001 or similar frameworks
- Certifications such as CEH, OSCP or CompTIA Security+ are a plus
Job Description – Tines SOAR Engineer
Job Title: Tines SOAR Engineer
Experience: 6+ Years
Employment Type: Contract
Job Location: India – Hybrid/Remote
Company: Prama.ai
About the Role
Prama.ai is looking for an experienced Tines SOAR Engineer to design, develop, and maintain security automation workflows for enterprise SOC environments. The ideal candidate should have strong hands-on experience with Tines SOAR, security operations, incident response, API integrations, and automation.
Key Responsibilities
- Design, develop, and maintain automation workflows (Tines Stories).
- Build and enhance security playbooks for incident response and alert handling.
- Develop integrations between Tines and SIEM, EDR/XDR, IAM, ITSM, and other security tools.
- Implement integrations using REST APIs, Webhooks, JSON, and OAuth.
- Automate repetitive SOC and security operations to improve incident response efficiency.
- Troubleshoot, monitor, and optimize Tines automation workflows.
- Collaborate with SOC, Security, Infrastructure, and IT teams.
- Support security automation use cases across enterprise environments.
Required Skills
- 6+ years of IT/Security experience with strong hands-on experience in Tines SOAR.
- Hands-on experience developing Tines Stories, Actions, Event Transformations, and API integrations.
- Strong understanding of SOC, Incident Response, Security Operations, and Security Automation.
- Strong knowledge of REST APIs, JSON, Webhooks, and OAuth.
- Experience with at least one SIEM:
- Microsoft Sentinel
- Splunk
- IBM QRadar
- Google Chronicle
- Experience with at least one EDR/XDR:
- Microsoft Defender
- CrowdStrike
- SentinelOne
- Cortex XDR
- Scripting experience in Python, JavaScript, or PowerShell.
- Experience with ServiceNow or Jira.
- Working knowledge of Windows/Linux environments.
- Good understanding of TCP/IP, DNS, HTTP/HTTPS.
- Knowledge of Active Directory, Entra ID, or Okta.
Preferred Skills
- Experience working with Banking/BFSI clients.
- Knowledge of Microsoft Security Stack.
- Understanding of Threat Intelligence and MITRE ATT&CK.
- Exposure to AWS or Azure Security.
- Experience with enterprise SOC automation and security integrations.
Preferred Certifications
- Tines Certification
- Microsoft SC-200
- CompTIA Security+ / CySA+
- Microsoft AZ-500
The recruiter has not been active on this job recently. You may apply but please expect a delayed response.
About Nerve Solutions
Nerve Solutions is a team of engineers building products for real-time risk management and surveillance in financial markets. Our solutions enable market participants to identify, monitor, and quantify risks and anomalies in live markets, allowing them to take corrective action at sub-second speeds.
We also develop products for automated trading and have become a trusted technology partner to some of the largest financial services organizations in the region.
About the Role
We are looking for a proactive and detail-oriented IT & Information Security Engineer to manage and maintain the organization's IT infrastructure while ensuring the security, availability, and reliability of our systems. The role involves providing technical support, administering hardware and software, strengthening cybersecurity practices, monitoring network activities, and implementing security controls to safeguard organizational assets.
The ideal candidate should have strong infrastructure knowledge, a security-first mindset, and the ability to troubleshoot technical issues while continuously improving the organization's IT environment.
Roles & Responsibilities
- Manage and maintain the organization's IT infrastructure, including hardware, software, servers, and network systems.
- Provide technical support to employees by troubleshooting hardware, software, network, and system-related issues.
- Configure, deploy, and maintain desktops, laptops, peripherals, printers, and other IT equipment.
- Set up user accounts, systems, and required software for new employees and support onboarding activities.
- Monitor network performance and employee network activities to ensure system security and compliance.
- Implement and maintain endpoint security solutions, antivirus tools, firewalls, and access control mechanisms.
- Perform regular system updates, security patching, vulnerability assessments, and preventive maintenance.
- Identify infrastructure risks and recommend security enhancements to minimize vulnerabilities.
- Maintain documentation for IT assets, software licenses, network configurations, security policies, and system inventories.
- Assist in implementing information security best practices, security audits, and compliance initiatives.
- Coordinate with internal teams to ensure IT services effectively support business operations.
- Stay updated with the latest cybersecurity threats, technologies, and industry best practices.
Required Skills
- 2–4 years of experience in IT Infrastructure, System Administration, or Information Security.
- Strong knowledge of Windows operating systems, networking, servers, and IT infrastructure.
- Experience troubleshooting hardware, software, network, and user-related issues.
- Knowledge of network security, endpoint protection, firewalls, VPNs, and vulnerability management.
- Experience with Active Directory, user access management, and system administration.
- Familiarity with Microsoft 365 administration is an added advantage.
- Understanding of backup, disaster recovery, and IT asset management.
- Strong analytical and problem-solving skills with attention to detail.
- Good communication and documentation skills.
- Ability to work independently and collaboratively in a fast-paced environment.
Preferred Qualifications
- Bachelor's degree in Information Technology, Computer Science, or a related field.
- Certifications such as CompTIA A+, Network+, Security+, Microsoft, CCNA, or equivalent will be an added advantage.
At Shipthis, we are building a better future for freight forwarders by evolving traditional operations into fully digital, efficient, and scalable systems. We’re a fast-growing product company where every individual has the opportunity to take ownership, move fast, and create real impact. If you enjoy solving complex problems, shaping products from the ground up, and influencing technical direction, Shipthis is the place for you.
Learn more at www.shipthis.co
Role Overview
We are looking for an associate-level SecOps Engineer to support security operations, compliance, endpoint management, cloud infrastructure, and DevOps engineering. The role will work closely with the CTO/CISO and engineering team. Security and compliance are core responsibilities; when those priorities are lighter, the engineer will focus on CI/CD, infrastructure automation, reliability, monitoring, performance, and cloud cost optimization.
What You’ll be Doing
Security Operations
- Monitor infrastructure, application, and security alerts and assist with incident investigation.
- Review access controls, privileged accounts, service accounts, permissions, and periodic access reviews.
- Support infrastructure hardening, logging, monitoring, backup, recovery, and other security controls.
- Track security issues and corrective actions through closure.
Vulnerability Management
- Run and review application and infrastructure vulnerability scans.
- Maintain a vulnerability register and coordinate remediation with engineering teams.
- Support VAPT and penetration-testing exercises and validate closure of findings.
- Monitor dependencies, containers, operating systems, and cloud infrastructure for known vulnerabilities and patching needs.
Compliance & Governance
- Support ongoing ISO/IEC 27001, SOC 2, GDPR, customer-security, and internal-policy requirements.
- Maintain audit evidence, control registers, security policies, procedures, risk items, and remediation records.
- Assist with internal/external audits, vendor assessments, customer security questionnaires, and asset inventories.
- Maintain evidence for access reviews, vulnerability management, incidents, onboarding/offboarding, backups, and infrastructure changes.
MDM & Endpoint Security
- Administer the company MDM platform and enroll/manage company laptops, desktops, and mobile devices.
- Maintain device inventory and monitor endpoint compliance.
- Enforce approved controls such as disk encryption, screen locks, password requirements, patching, and endpoint protection.
- Support employee device onboarding/offboarding, approved application deployment, lost/stolen-device procedures, and remote wipe where authorized.
- Maintain endpoint security and MDM evidence required for audits and troubleshoot enrollment or policy issues.
DevOps, CI/CD & Cloud
- Maintain and improve CI/CD pipelines, deployment workflows, build times, caching, and rollback processes.
- Support production and non-production cloud infrastructure, networking, DNS, TLS certificates, IAM, and secrets.
- Automate repetitive deployment, infrastructure, security, and compliance tasks.
- Improve monitoring, logging, alerting, reliability, resource utilization, and cloud costs.
- Troubleshoot pipeline, deployment, and infrastructure issues and participate in root-cause analysis.
Required Fundamentals
- Basic knowledge of Linux, networking, HTTP/HTTPS, DNS, TLS, Git, Docker, cloud computing, APIs, and web applications.
- Understanding of IAM, MFA, least privilege, vulnerabilities/CVEs, encryption, logging, patching, and secrets management.
- Strong troubleshooting, ownership, attention to detail, and willingness to learn.
Desired Qualifications
- 1–2 years of experience with strong fundamentals are welcome.
- Basic scripting knowledge in Python, Bash, or similar.
- Interest in cybersecurity, cloud infrastructure, automation, and troubleshooting.
- Exposure to AWS/GCP/Azure, Terraform, GitHub Actions, Cloudflare, OWASP, vulnerability scanners, MDM, ISO 27001, or SOC 2 is a plus, not mandatory.
We Welcome Candidates:
- Who can join immediately
- Female candidates returning to work after a career break are strongly encouraged.
We are an equal opportunity employer and are committed to fostering diversity and inclusivity. We do not discriminate based on race, religion, color, gender, sexual orientation, age, marital status, or disability status.
Job Synopsys
Location: Bangalore
Job Type: Full-time, Permanent
Experience: 1-2 years
Industry: Software Product






