Birlasoft Limited

Technical Lead-Cybersecurity

Birlasoft Limited Noida, Uttar Pradesh, India

IT Services and IT Consulting · 10,001+ employees

Sep 15
security Senior (5-10 yrs) Full-time India
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Technical Lead will monitor, investigate, and respond to security alerts while performing threat hunting and incident analysis. They are also responsible for maintaining SIEM correlation rules and developing SOC playbooks to improve detection capabilities.

What they look for

Security Incident Response SIEM Operations Threat Hunting Incident Investigation Malware Analysis IOC Analysis EDR XDR Log Analysis Network Security Monitoring Cloud Security Monitoring Email Security Phishing Analysis Vulnerability Management Digital Forensics MITRE ATT&CK Framework

Requirements

The ideal candidate must have hands-on experience with SIEM, EDR, and cloud security monitoring tools. Proficiency in log analysis, malware triage, and incident response methodologies is required to effectively manage enterprise security threats.

Full description

Area(s) of responsibility

Role Summary

We are seeking an experienced L2 Security Incident Response Analyst to support Security Operations Center (SOC) activities, including threat monitoring, incident investigation, threat hunting, detection analysis, malware triage, and incident response. The ideal candidate will have hands-on experience with SIEM, EDR, cloud security monitoring, log analysis, and cyber threat detection, along with the ability to investigate and respond to security incidents across enterprise environments.

Key Responsibilities

  • Monitor, investigate, and respond to security alerts and incidents generated from SIEM, EDR, IAM, Cloud Security, and security monitoring platforms.
  • Perform detailed incident analysis, triage, containment, eradication, and recovery activities.
  • Conduct threat hunting activities to identify suspicious behavior, advanced threats, and potential security breaches.
  • Analyze logs, network traffic, endpoint activities, and cloud events to identify indicators of compromise (IOCs).
  • Investigate malware, phishing, ransomware, insider threats, account compromise, and unauthorized access incidents.
  • Correlate security events from multiple security tools and data sources to determine attack scope and impact.
  • Escalate critical incidents and coordinate with infrastructure, cloud, application, and business stakeholders during incident response activities.
  • Create and maintain SIEM correlation rules, use cases, detection logic, and alert tuning recommendations.
  • Support forensic investigations and root cause analysis.
  • Prepare incident reports, executive summaries, and post-incident review documentation.
  • Validate security controls and recommend improvements to detection and response capabilities.
  • Participate in vulnerability remediation validation and risk reduction activities.
  • Support security audits, compliance initiatives, and governance requirements.
  • Develop and maintain SOC runbooks, playbooks, and operational procedures.
  • Assist in continuous improvement of SOC processes, threat detection, and response capabilities.

Required Skills

  • Security Incident Monitoring & Response
  • SIEM Operations & Analysis
  • Threat Hunting
  • Incident Investigation & Triage
  • Malware Analysis Fundamentals
  • IOC Analysis & Threat Intelligence
  • Endpoint Detection & Response (EDR/XDR)
  • Log Analysis & Event Correlation
  • Network Security Monitoring
  • Cloud Security Monitoring
  • Email Security & Phishing Analysis
  • Vulnerability Management Fundamentals
  • Digital Forensics Concepts
  • MITRE ATT&CK Framework
  • Cyber Kill Chain Methodology

Similar roles