SecOps Engineer / Security Operations / SOC Engineer
Infra360 · Head Office · India · On-site
Pay: INR 800,000 – 1,000,000 a year
Posted Sep 30, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
About Infra360
Infra360 is a Managed Cloud Service Provider helping businesses build, secure and operate their cloud and technology environments across Cloud, DevOps, SRE, Security, FinOps and Managed Services .
We are building our Security Operations and MDR capabilities and are looking for a hands-on SecOps Engineer to join the team.
About the Role
As a SecOps Engineer, you will be responsible for security monitoring, alert investigation, threat hunting, detection engineering and incident response across customer environments.
This is not a traditional alert-monitoring role . We are looking for someone who can investigate security events, understand attacker behavior, identify the root cause, improve detections and support effective response.
You will work across SIEM, EDR/XDR, cloud, identity, endpoint and network security telemetry .
Key Responsibilities
1. Security Monitoring & Alert Investigation
Monitor and investigate security alerts across customer environments.
Perform alert triage and determine severity and business impact.
Correlate events across endpoint, identity, network and cloud sources.
Investigate suspicious activity and identify false positives.
Maintain accurate incident timelines and investigation documentation.
Work within defined security processes and customer SLAs.
2. SIEM / XDR Operations
Work with SIEM/XDR platforms such as Microsoft Sentinel, Microsoft Defender XDR, Wazuh, Splunk, Elastic, CrowdStrike, SentinelOne, Google SecOps or similar.
Analyze logs and security telemetry.
Develop and tune detection and correlation rules.
Monitor log-source health and identify visibility gaps.
Improve alert quality and detection coverage.
3. Incident Response
Investigate and support response to incidents including:
Malware and ransomware
Account compromise
Phishing and business email compromise
Credential attacks
Privilege escalation
Lateral movement
Suspicious PowerShell/scripts
Command-and-control activity
Cloud security incidents
Data-exfiltration activity
The engineer should be able to understand what happened, how it happened, what is affected and what needs to be done next .
4. Threat Hunting
Conduct proactive threat hunting using:
MITRE ATT&CK
IOCs and TTPs
Suspicious processes
Authentication anomalies
PowerShell/script activity
C2 indicators
Credential abuse
Cloud activity
Identify threats that may not have been detected through existing alerts.
5. Detection Engineering
Develop and improve SIEM detection rules.
Create and tune correlation rules.
Develop behavioral and IOC-based detections.
Map detections to MITRE ATT&CK .
Identify detection gaps and improve coverage.
Convert incident learnings into new detection use cases.
Knowledge of Sigma is preferred.
6. EDR/XDR Investigation
Analyze processes, process trees, files, hashes and network connections.
Investigate endpoint behavior and persistence mechanisms.
…