Senior IT Security Analyst

Client of Forstaffing Published: August 5, 2026
Location
Pune, India
Job Type
Category

Description

Must-Have skills:

BE/B.Tech in CS/IT/ECE/EEE or MCA/M.Sc. in CS/IT

Hands-on expertise across a wide range of cybersecurity tools (L3 level)

Threat hunting, threat detection, threat intelligence

Practical application of MITRE ATT&CK framework for threat mapping

Vulnerability management ( Mandatory(

KQL for advanced security analytics and monitoring ( Mandatory)

Security & phishing incident handling, high-level incident response

Strong hands-on experience with CrowdStrike ( Mandatory)

SIEM log source onboarding

Fine-tuning detection rules, developing detection logic

 

Interview Process

 

L1-Interview (Technical Discussion)

L2-Interview (Technical Discussion)

F2F-LAB- Hands on Experience on built case scenario (if required)

F2F-Managerial and HR Round

 

working model : 3days wfo and 2 days wfh

 

 

About the vacancy:

Designation: Senior IT Security Analyst

Required Experience:8-13 years

Location: Pune

 

Job Description:

 

  1. Your Skills:
  • Significant experience in SOC, CERT, or CSIRT environments, with expertise in SIEM

administration, threat hunting, detection engineering, and incident response.

  • Strong expertise in configuring, optimizing, and maintaining Microsoft security products,

including Sentinel, Defender for Cloud, Endpoint, Identity, Office 365, Exchange, and Azure

Active Directory.

  • Proficiency in log sources onboarding in SIEM, log management, developing consolidated

security dashboards and developing Playbook to support continuous monitoring.

  • Proficiency in creating and simulating hypothetical threat scenarios to anticipate and combat

potential attack vectors.

  • In-depth understanding and practical application of the MITRE ATT&CK framework for mapping

detection rules and identifying attacker tactics, techniques, and procedures (TTPs).

  • Practical knowledge of security technologies, including firewalls, IDS/IPS, SIEM, endpoint

detection, anti-malware, and vulnerability assessment tools.

  • Solid understanding of networks, cloud infrastructures, operating systems (Windows, Linux),

and evolving cyberattack methods.

  • Experience in correlating threat intelligence feeds with detection engineering to identify and

mitigate advanced threats.

  • Proven ability to analyze large volumes of security logs and data to craft precise, high-fidelity

detection rules while reducing false positives.

  • Excellent communication and collaboration skills to effectively share findings and work with

cross-functional teams.

  • Passionate about proactive cybersecurity measures, with a strong desire to stay updated on

emerging threats and technologies.

 

  1. Behaviors:
  • A high level of collaboration skills with other cross functional global teams.
  • Confidence in expressing your ideas and input to the team.
  • Open to learn and work on different/new technologies.
  • Agile in nature.
  • Self-motivated and proactive.

 

  1. Role and Responsibilities:

 

  • Incident Response and Collaboration:
  1. Collaborate with SOC, CERT, or CSIRT teams for effective incident monitoring and

response.

  1. Investigate and respond to cybersecurity incidents, including forensic analysis of

attack patterns.

  • SIEM Administration:
  1. Provide ongoing support for SIEM Architecture, ensuring efficient log ingestion,

parsing, and normalization to enhance threat visibility and detection capabilities.

  1. Designed and customized automated playbooks and interactive dashboards in SIEM to

meet specific security monitoring and incident response requirements.

  • Threat Intelligence Analysis:
  1. Gather, process, and analyze threat intelligence feeds to identify emerging threats.
  2. Proactively communicate relevant threat scenarios and provide actionable insights.
  • Threat Detection Development:
  1. Develop and fine-tune advanced KQL queries and analytics rules in Microsoft Sentinel

to detect sophisticated attack vectors.

  1. Build and test hypothetical threat scenarios to enhance threat detection capabilities.
  2. Optimize detection systems to minimize false positives and maximize precision.
  • Incident Response and Collaboration:
  1. Collaborate with SOC, CERT, or CSIRT teams for effective incident monitoring and

response.

  1. Investigate and respond to cybersecurity incidents, including forensic analysis of

attack patterns.

  • Security Tool Management:
  1. Configure, monitor, and maintain security tools such as SIEM (Microsoft Sentinel),

Defender for Cloud, antivirus solutions, and consolidated security dashboards.

  • Continuous Improvement:
  1. Participate in developing and implementing security concepts, hardening guidelines,

and monitoring systems.

  1. Perform penetration tests, vulnerability assessments, and audits to ensure robust

security measures.

  1. Contribute to the creation and refinement of SOC policies, processes, and procedures.
  1. Desirable Certifications:

 

  • Microsoft Certified: Security Operations Analyst Associate – SC 200
  • CEH
Apply
Drop files here browse files ...

Related Jobs

October 9, 2024
Are you sure you want to delete this file?
/