SOC Analyst | IT Security | Pune at Searce Inc · Pune · 2 - 5 years · Profitable · Posted 14 Apr 2026

Job Summary: We are seeking a proactive and technically skilled information security (SOC) Engineer/Analyst to monitor, detect, and respond to cybersecurity threats in real-time. The ideal candidate will have strong analytical skills, be detail-oriented, and possess a sound understanding of threat landscapes, SIEM tools, and incident response. The ideal candidate will possess a strong foundational understanding of cybersecurity governance, robust technical skills in security operations, and a commitment to staying abreast of the evolving threat landscape and internal security requirements.
Key Responsibilities
- Monitor security events and alerts from SIEM and other security tools.
- Perform initial triage and investigation of potential threats or anomalous behavior.
- Escalate incidents according to severity and defined procedures.
- Document incidents, provide root cause analysis, and maintain detailed logs.
- Analyze threat intelligence feeds and correlate with internal data.
- Assist in threat hunting and vulnerability management activities.
- Support continuous improvement of SOC processes and playbooks.
- Collaborate with other IT and Security teams for incident resolution.
- Assist in developing and tuning SIEM rules, queries, and dashboards for threat detection.
- Contribute to vulnerability management and secure configuration of internal systems and cloud environments.
- Support the testing and execution of recovery plans for security systems and data.
- Document incident findings, remediation steps, and contribute to post-incident reviews.
Required Skills & Qualifications:
- Bachelor’s degree in Computer Science, Cybersecurity, or related field.
- 2–5 years of experience in a SOC environment or similar security operations role.
- Familiarity with SIEM tools (e.g., Splunk, QRadar, Sentinel).
- Understanding of TCP/IP, firewalls, IDS/IPS, and common attack vectors.
- Knowledge of malware, phishing, ransomware, and social engineering tactics.
- Hands-on experience with endpoint protection, network monitoring, and forensic tools.
- Excellent communication and documentation skills.
- Preferred Certifications:
- CompTIA Security+ or CySA+
- Vendor-specific SIEM certifications.

About Searce Inc
About
What is ‘searce’
Searce means ‘a fine sieve’ & indicates ‘to refine, to analyze, to improve’. It signifies our way of working: To improve to the finest degree of excellence, ‘solving for better’ every time. Searcians are passionate improvers & solvers who love to question the status quo.
The primary purpose of all of us, at Searce, is driving intelligent, impactful & futuristic business outcomes using new-age technology. This purpose is driven passionately by HAPPIER people who aim to become better, everyday.
What we do
Searce is a modern tech consulting firm that empowers clients to futurify their businesses, leveraging Cloud, AI & Analytics.
- We are a category defining niche’ cloud-native technology consulting company, specializing in modernizing (improve, automate & transform) the full-scope of infra, app, process & work
- We partner with clients in their ‘beyond x’ journey to drive intelligent, impactful & futuristic business outcomes
- We are the most preferred tech partner of choice when it comes to ‘solving for better’ for the new-age tech startups & digital enterprises, leading disruption in their industries
- Our Service Offerings: We offer Advanced Cloud, Data & App Modernization, Cloud Consulting, Management & Improvement (DevOps, SysOps & Cloud Managed Services), Applied AI & Analytics services
- As one of the top 5 niche’ full scope global partners for Google Cloud & a preferred partner for AWS, we are the most preferred ‘engineering-led’ tech company of choice when it comes to solving complex business problems.
Who we are
We are passionate improvers, solvers & futurists. Driven by our engineering excellence mindset, we care most about delivering intelligent, impactful & futuristic business outcomes. Searcians are motivated by continuous improvement & solving for better in everything we do.
At the core, a Searcian is self-driven to become better, everyday. In passionate pursuit of the finest degree of excellence we drive exceptional outcomes in everything we do.
We believe that trust is the most important value. We also believe that we need to ‘earn the trust’, everytime one engages with us. And earning trust for us is far more important than anything else. We aim to be the *most trusted* tech consulting partner for our clients.
We are HAPPIER at heart. Humble, Adaptable, Positive, Passionate, Innovative, Excellence focused, & Responsible. We live the HAPPIER Culture Code.
Being HAPPIER.
How we work
- Customers. Partners. Our aim is to build relationships with customers for life. And meaningfully improve the life of every customer.
- We do what we say. We say what we do. We are uncomfortably honest and transparent. Being genuine wins trust & makes people happier.
- Mistakes are encouraged. We make mistakes. Tons of those. Everyday. And we don’t mind apologizing to our juniors, peers or superiors. We are no ego-doers.
- Underpromise. Overdeliver. We work with a deep desire to go above and beyond in everything we do. Everytime.
So, If you are passionate about tech, future & what you read above (we really are!), apply here to experience the ‘Art of Possible’
Connect with the team
Similar jobs (8)
This role will be permanent with NAM info and deploy to client location Chennai.
Work Mode: WORK FROM OFFICE
Offer salary can offer on a decent hike
Role Descriptions:
Exp Range: 6-10 years
Primary Competency : Terraform, Hashi Sentinel (IaC/PaC), Kubernetes (GKE/EKS)
City Locations: Bengaluru or Chennai
Key Responsibilities*
Experience Required: 6-10
Role Descriptions:
Security Monitoring & Incident Response
Investigate and analyze security alerts escalated by L1 SOC analysts.
Perform triage, containment, eradication, and recovery activities for security incidents.
1. Perform in-depth analysis of security alerts escalated from L1
2. Investigate suspicious activities using SIEM, EDR, and threat intelligence tools
3. Correlate events across multiple log sources (firewalls, endpoints, IAM, cloud logs)
4. Validate true positives and recommend reducing false positives
5. Lead triage and response for medium to high severity incidents
6. Coordinate with IT, network, and application teams during incidents and support deep investigations when required
7. Conduct proactive threat hunting based on TTPs (e.g., MITRE ATT&CK)
8. Fine-tuning and optimize SIEM use cases to reduce false positives
9. Develop new correlation rules and detection logic
10. Document incidents, findings, and response actions
11. Prepare weekly , monthly reports for SOC leadership and stakeholders
Desire candidate
- Candidate should have valid PF.
The Security Analyst assists the Data Security team to help ensure the security of the company and its clients. Looking for immediate joiners.
KEY RESPONSIBILITIES
All employees are expected to use good business judgment and appropriate discretion and decision making while performing responsibilities of the position, and to incorporate EVA’s Core Beliefs in their daily work.
- Performs daily health checks as documented by the IT Security team.
- Supports the Security team by documenting and performing support tasks.
- Participates in change management, incident management, audit and business continuity processes.
- Plans and implements security policies and procedures to protect computer systems, networks and data from unauthorized access.
- Participates in internal and external compliance (SOC 2) audits.
- Recommends security enhancements.
Job specifics:
- Familiarity with standard security concepts, practices and procedures.
- Knowledge of Windows operating systems.
- Strong Documentation, communication skills and attention to detail.
- Able to work independently and as a part of a team to deliver completed projects on-time.
- Identifies ways to continuously improve own and/or company performance.
- Knowledge of security toolsets
- Knowledge of compliance activities (GDPR, SOC 2, ISO:27001).
- Knowledge of database security.
- Knowledge of SIEM technology and security event correlation and monitoring.
- Experience with AWS.
- Proficient with computer software including Salesforce
EDUCATION & EXPERIENCE
- Bachelor’s Degree in computer science, mathematics, Information Systems or equivalent experience preferred.
- Minimum of 3 years of hands-on IT Security & Audit experience.
- Professional IT Security Certifications are strongly preferred, such as Security+, CISSP, CISM, CISA, GSEC, etc.
Job Summary:
We are looking for an experienced OpenText ArcSight SIEM / SOAR / UBA L2-L3 Engineer to manage and support security platforms in SOC/MSSP environment. The role involves day-to-day administration, troubleshooting, configuration and optimization of ArcSight platforms.
Key Responsibilities
- Administer and monitor OpenText ArcSight ESM/SIEM, SmartConnectors, SOAR and UBA/ArcSight Intelligence.
- Manage SIEM rules, filters, Active Lists, dashboards, reports and correlation use cases.
- Monitor EPS, event flow, connector health, system performance and log ingestion.
- Troubleshoot event collection, parsing, correlation and integration issues.
- Configure and troubleshoot ArcSight SmartConnectors and log sources.
- Manage and troubleshoot SOAR playbooks, integrations and automated workflows.
- Support UBA/Intelligence data ingestion, analytics and integration with SIEM.
- Perform L2/L3 troubleshooting, RCA and resolution of platform-related incidents.
- Support upgrades, patches, configuration changes and platform optimization.
- Coordinate with SOC, infrastructure, customer and OEM/OpenText support teams.
- Maintain technical documentation, incident records and RCA reports.
Required Skills
- 3–6 years of hands-on experience with OpenText ArcSight SIEM/ESM.
- Strong experience in ArcSight administration and troubleshooting.
- Hands-on experience with SmartConnectors, EPS, correlation rules, Active Lists and event flow.
- Working experience with ArcSight SOAR and UBA/ArcSight Intelligence.
- Good knowledge of Linux/Unix and networking fundamentals.
- Understanding of Syslog, CEF, TCP/IP, SSL/TLS and REST APIs.
- Strong analytical, troubleshooting and problem-solving skills.
- Experience in SOC/MSSP or managed security services environment preferred.
- OpenText/ArcSight certification will be an added advantage.
Candidate Profile
The candidate should be hands-on, technically strong and capable of independently handling L2/L3 production issues, platform administration, troubleshooting and escalations in a security operations environment.
About the role
You will create and validate the detection content that protects our customers: IDPS signatures, application control rules, and DLP rules. This is a hands-on role in our security lab, where you will generate real attack traffic, research vulnerabilities and applications, and make sure every rule is accurate, effective, and ready for production.
What you'll do
Write security rules
- Write IDPS signatures for exploits, malware, command-and-control traffic, and network attacks, with the right severity, action (alert / block / reject), and protocol scope
- Build application control rules to identify and control social media, streaming, file sharing, remote access, unsanctioned SaaS, and AI tools
- Create DLP rules to detect sensitive data (personal and financial data, confidential documents, source code) across web, email, and file transfer channels
Test and validate
- Set up test scenarios in our lab and generate traffic using browsers, command-line tools, packet captures, and safe proof-of-concept exploits
- Confirm that each rule triggers and that logs show the correct rule, severity, action, and source
- Test against normal everyday traffic to find and fix false positives before rules ship
- Build and maintain a repeatable test set so rules keep working after product updates
Research and document
- Track new CVEs, exploit techniques, and emerging applications, and turn them into working detections
- Study public r
- Study public rulesets to learn coverage patterns and find gaps in our own
- Write a short validation note for each batch: what it detects, how it was tested, and what it doesn't cover
What we're looking for
- 2-5 years of hands-on experience writing detection rules or signatures with Snort, Suricata, Zeek, YARA, Sigma, or similar
- Strong networking fundamentals: TCP/IP, HTTP/HTTPS, DNS, TLS, and packet analysis with Wireshark or pcap tools
- Experience testing rules with PoC exploits and tuning them to reduce false positives
- Exposure to CVE and vulnerability research, with the ability to read advisories and turn them into detections
- Working knowledge of Python or Bash for test automation, and comfort with Linux
- Clear written communication, since you'll document what each rule covers and what it doesn't
Good to have
- Experience with deep packet inspection, application identification (nDPI or similar), or DLP regex and pattern work
- Background at a network security vendor (firewall, IPS, NGFW, secure web gateway)
- Public work such as GitHub rules, blog posts, CVE credits, or CTF participation
This role is not
A SOC monitoring, alert triage, or pure penetration testing role. We are looking for people who write and test detection rules.
Job Description – Tines SOAR Engineer
Job Title: Tines SOAR Engineer
Experience: 6+ Years
Employment Type: Contract
Job Location: India – Hybrid/Remote
Company: Prama.ai
About the Role
Prama.ai is looking for an experienced Tines SOAR Engineer to design, develop, and maintain security automation workflows for enterprise SOC environments. The ideal candidate should have strong hands-on experience with Tines SOAR, security operations, incident response, API integrations, and automation.
Key Responsibilities
- Design, develop, and maintain automation workflows (Tines Stories).
- Build and enhance security playbooks for incident response and alert handling.
- Develop integrations between Tines and SIEM, EDR/XDR, IAM, ITSM, and other security tools.
- Implement integrations using REST APIs, Webhooks, JSON, and OAuth.
- Automate repetitive SOC and security operations to improve incident response efficiency.
- Troubleshoot, monitor, and optimize Tines automation workflows.
- Collaborate with SOC, Security, Infrastructure, and IT teams.
- Support security automation use cases across enterprise environments.
Required Skills
- 6+ years of IT/Security experience with strong hands-on experience in Tines SOAR.
- Hands-on experience developing Tines Stories, Actions, Event Transformations, and API integrations.
- Strong understanding of SOC, Incident Response, Security Operations, and Security Automation.
- Strong knowledge of REST APIs, JSON, Webhooks, and OAuth.
- Experience with at least one SIEM:
- Microsoft Sentinel
- Splunk
- IBM QRadar
- Google Chronicle
- Experience with at least one EDR/XDR:
- Microsoft Defender
- CrowdStrike
- SentinelOne
- Cortex XDR
- Scripting experience in Python, JavaScript, or PowerShell.
- Experience with ServiceNow or Jira.
- Working knowledge of Windows/Linux environments.
- Good understanding of TCP/IP, DNS, HTTP/HTTPS.
- Knowledge of Active Directory, Entra ID, or Okta.
Preferred Skills
- Experience working with Banking/BFSI clients.
- Knowledge of Microsoft Security Stack.
- Understanding of Threat Intelligence and MITRE ATT&CK.
- Exposure to AWS or Azure Security.
- Experience with enterprise SOC automation and security integrations.
Preferred Certifications
- Tines Certification
- Microsoft SC-200
- CompTIA Security+ / CySA+
- Microsoft AZ-500
At Shipthis, we are building a better future for freight forwarders by evolving traditional operations into fully digital, efficient, and scalable systems. We’re a fast-growing product company where every individual has the opportunity to take ownership, move fast, and create real impact. If you enjoy solving complex problems, shaping products from the ground up, and influencing technical direction, Shipthis is the place for you.
Learn more at www.shipthis.co
Role Overview
We are looking for an associate-level SecOps Engineer to support security operations, compliance, endpoint management, cloud infrastructure, and DevOps engineering. The role will work closely with the CTO/CISO and engineering team. Security and compliance are core responsibilities; when those priorities are lighter, the engineer will focus on CI/CD, infrastructure automation, reliability, monitoring, performance, and cloud cost optimization.
What You’ll be Doing
Security Operations
- Monitor infrastructure, application, and security alerts and assist with incident investigation.
- Review access controls, privileged accounts, service accounts, permissions, and periodic access reviews.
- Support infrastructure hardening, logging, monitoring, backup, recovery, and other security controls.
- Track security issues and corrective actions through closure.
Vulnerability Management
- Run and review application and infrastructure vulnerability scans.
- Maintain a vulnerability register and coordinate remediation with engineering teams.
- Support VAPT and penetration-testing exercises and validate closure of findings.
- Monitor dependencies, containers, operating systems, and cloud infrastructure for known vulnerabilities and patching needs.
Compliance & Governance
- Support ongoing ISO/IEC 27001, SOC 2, GDPR, customer-security, and internal-policy requirements.
- Maintain audit evidence, control registers, security policies, procedures, risk items, and remediation records.
- Assist with internal/external audits, vendor assessments, customer security questionnaires, and asset inventories.
- Maintain evidence for access reviews, vulnerability management, incidents, onboarding/offboarding, backups, and infrastructure changes.
MDM & Endpoint Security
- Administer the company MDM platform and enroll/manage company laptops, desktops, and mobile devices.
- Maintain device inventory and monitor endpoint compliance.
- Enforce approved controls such as disk encryption, screen locks, password requirements, patching, and endpoint protection.
- Support employee device onboarding/offboarding, approved application deployment, lost/stolen-device procedures, and remote wipe where authorized.
- Maintain endpoint security and MDM evidence required for audits and troubleshoot enrollment or policy issues.
DevOps, CI/CD & Cloud
- Maintain and improve CI/CD pipelines, deployment workflows, build times, caching, and rollback processes.
- Support production and non-production cloud infrastructure, networking, DNS, TLS certificates, IAM, and secrets.
- Automate repetitive deployment, infrastructure, security, and compliance tasks.
- Improve monitoring, logging, alerting, reliability, resource utilization, and cloud costs.
- Troubleshoot pipeline, deployment, and infrastructure issues and participate in root-cause analysis.
Required Fundamentals
- Basic knowledge of Linux, networking, HTTP/HTTPS, DNS, TLS, Git, Docker, cloud computing, APIs, and web applications.
- Understanding of IAM, MFA, least privilege, vulnerabilities/CVEs, encryption, logging, patching, and secrets management.
- Strong troubleshooting, ownership, attention to detail, and willingness to learn.
Desired Qualifications
- 1–2 years of experience with strong fundamentals are welcome.
- Basic scripting knowledge in Python, Bash, or similar.
- Interest in cybersecurity, cloud infrastructure, automation, and troubleshooting.
- Exposure to AWS/GCP/Azure, Terraform, GitHub Actions, Cloudflare, OWASP, vulnerability scanners, MDM, ISO 27001, or SOC 2 is a plus, not mandatory.
We Welcome Candidates:
- Who can join immediately
- Female candidates returning to work after a career break are strongly encouraged.
We are an equal opportunity employer and are committed to fostering diversity and inclusivity. We do not discriminate based on race, religion, color, gender, sexual orientation, age, marital status, or disability status.
Job Synopsys
Location: Bangalore
Job Type: Full-time, Permanent
Experience: 1-2 years
Industry: Software Product
Position Title: Network Operations Center (NOC) Analyst
Experience Required: 3+ Years
Working Mode: Remote
Preferred Location: Hyderabad / Bangalore / Chennai
Shift Timing: Rotational Shifts (US Timings)
About the Role
We are looking for a proactive and technically strong NOC Analyst to support MSP clients' enterprise network infrastructure. The ideal candidate should have hands-on experience in network monitoring, monitoring tool administration, incident management, basic network troubleshooting, documentation, and coordination with ISP, Field Engineers, and customers while ensuring maximum network availability and SLA compliance.
Mandatory Requirements
· Strong communication skills with customers and technical teams.
· Minimum 3+ years of experience in Enterprise NOC / Network Operations.
· Experience working in 24×7 rotational shift environments.
· Good understanding of Enterprise Network Monitoring and ITIL-based Incident Management.
· MSP environment experience.&ITIL Foundation certification.
· Exposure to AWS/Azure networking is an added advantage.
· Valid CCNA Certification.( Preferred )
Technical Skills Required
Networking: TCP/IP, DNS, DHCP, Subnetting, IPv4 Addressing, LAN/WAN, VPN
Routing & Switching: Basic troubleshooting of OSPF, BGP; good understanding of VLAN, STP and Trunking
Monitoring Protocols: SNMP, Syslog, NetFlow, Telemetry
Monitoring Tools: SolarWinds, LogicMonitor, Auvik, PRTG, Zabbix, Nagios, ManageEngine
Ticketing Tools: ServiceNow, ConnectWise, Jira, Zendesk
Basic Knowledge: Windows Server, Linux, Network Devices, Firewall Concepts
Key Responsibilities
Network Monitoring
· Monitor enterprise network infrastructure using monitoring platforms.
· Integrate and onboard new network devices/nodes into monitoring tools.
· Configure and maintain monitoring templates, thresholds, and alert profiles.
· Ensure continuous availability of monitored infrastructure.
Incident Management
· Monitor alerts and incidents generated from monitoring platforms.
· Perform ticket triaging, categorization and prioritization.
· Perform Level-1 and basic Level-2 network troubleshooting.
· Escalate incidents appropriately and ensure SLA compliance.
Network Troubleshooting
· Basic troubleshooting of OSPF, BGP, Routing & Switching.
· Troubleshoot DNS, DHCP, TCP/IP, LAN/WAN, VPN and network reachability.
· Perform subnet calculations and IP addressing validation.
Monitoring Protocols
· Hands-on knowledge of SNMP, Syslog, NetFlow and Telemetry.
· Understand device discovery, performance monitoring, fault monitoring and alert generation.
Coordination & Documentation
· Coordinate with Field Engineers, ISP providers, Client Technical Teams and internal L2/L3 teams.
· Track incidents until complete resolution.
· Prepare RCA, SOP, Incident Reports, Shift Handover Documents, Knowledge Base Articles and Weekly/Monthly Operational Reports.
Educational Qualification
Bachelor's Degree in Computer Science, Information Technology, Electronics, or a related field.
Notice Period
Immediate Joiners / Short Notice Candidates Preferred.
Role Overview
We are looking for an experienced Network Security Engineer to design, implement, maintain, and secure enterprise network infrastructure. The role requires a strong understanding of network security principles, hands-on experience with security technologies, and the ability to troubleshoot complex network and security issues.
The ideal candidate will work closely with network, infrastructure, cloud, application, and security teams to ensure secure, resilient, and highly available network environments. The candidate should be comfortable handling security incidents, performing root-cause analysis, implementing security controls, and contributing to continuous improvement of the organization's network security posture.
Key Responsibilities
- Design, implement, configure, and maintain enterprise network security infrastructure.
- Manage and support network security technologies including firewalls, VPNs, IDS/IPS, secure gateways, and network access controls.
- Configure and maintain security policies, access rules, NAT, VPN tunnels, and related network security controls.
- Monitor network traffic and security events to identify potential threats, anomalies, and unauthorized access.
- Troubleshoot complex network connectivity and security-related issues and perform root-cause analysis.
- Investigate and respond to network security incidents in coordination with security and infrastructure teams.
- Review firewall and network security rules regularly and ensure they follow established security standards and business requirements.
- Support secure connectivity across data centers, corporate networks, remote locations, cloud environments, and third-party networks.
- Participate in network security assessments, vulnerability remediation, and security hardening activities.
- Implement and maintain network segmentation and access-control mechanisms.
- Work with internal teams to assess security requirements for new applications, infrastructure, and network changes.
- Participate in change management, implementation, and post-change validation activities.
- Maintain network security documentation, architecture diagrams, configurations, and operational procedures.
- Contribute to security improvement initiatives, automation, standardization, and operational efficiency.
- Work with vendors and technology partners for issue resolution, upgrades, and technical escalations.
- Ensure network security operations align with organizational policies, industry standards, and compliance requirements.
Required Skills
- Strong experience in network security engineering and enterprise networking.
- Good understanding of TCP/IP, DNS, DHCP, HTTP/HTTPS, routing, switching, VLANs, and network protocols.
- Hands-on experience with enterprise firewalls and security gateways.
- Strong understanding of VPN technologies, IPsec, SSL/TLS, NAT, and access-control policies.
- Experience with IDS/IPS, network monitoring, traffic analysis, and security event investigation.
- Experience troubleshooting network and security issues across complex environments.
- Good understanding of network security architecture, segmentation, and secure connectivity.
- Experience with incident management, change management, and root-cause analysis.
- Familiarity with security best practices, vulnerability management, and network hardening.
- Strong analytical, troubleshooting, and problem-solving skills.
- Good written and verbal communication skills with the ability to work effectively with technical and non-technical stakeholders.
Preferred Skills
- Experience with security technologies from vendors such as Palo Alto, Fortinet, Cisco, Check Point, or similar.
- Exposure to cloud networking and cloud security across AWS, Azure, or GCP.
- Knowledge of Zero Trust, SASE, SD-WAN, or network access control concepts.
- Experience with security monitoring/SIEM platforms.
- Exposure to scripting or automation using Python, PowerShell, or similar technologies.
- Relevant certifications such as CCNA/CCNP Security, PCNSE, Fortinet certifications, or equivalent are an advantage.
Key Competencies
- Network Security Engineering
- Enterprise Network Troubleshooting
- Firewall & VPN Management
- Security Incident Handling
- Network Monitoring & Analysis
- Security Hardening
- Root-Cause Analysis
- Risk & Vulnerability Awareness
- Change & Configuration Management
- Stakeholder Communication
- Problem Solving
- Documentation & Process Discipline










