JobRaahGet matched free

Jobs

SecOps Engineer / Security Operations / SOC Engineer

Infra360 · Head Office · India · On-site

Pay: INR 800,000 – 1,000,000 a year

Posted Sep 30, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

About Infra360 Infra360 is a Managed Cloud Service Provider helping businesses build, secure and operate their cloud and technology environments across Cloud, DevOps, SRE, Security, FinOps and Managed Services . We are building our Security Operations and MDR capabilities and are looking for a hands-on SecOps Engineer to join the team. About the Role As a SecOps Engineer, you will be responsible for security monitoring, alert investigation, threat hunting, detection engineering and incident response across customer environments. This is not a traditional alert-monitoring role . We are looking for someone who can investigate security events, understand attacker behavior, identify the root cause, improve detections and support effective response. You will work across SIEM, EDR/XDR, cloud, identity, endpoint and network security telemetry . Key Responsibilities 1. Security Monitoring & Alert Investigation Monitor and investigate security alerts across customer environments. Perform alert triage and determine severity and business impact. Correlate events across endpoint, identity, network and cloud sources. Investigate suspicious activity and identify false positives. Maintain accurate incident timelines and investigation documentation. Work within defined security processes and customer SLAs. 2. SIEM / XDR Operations Work with SIEM/XDR platforms such as Microsoft Sentinel, Microsoft Defender XDR, Wazuh, Splunk, Elastic, CrowdStrike, SentinelOne, Google SecOps or similar. Analyze logs and security telemetry. Develop and tune detection and correlation rules. Monitor log-source health and identify visibility gaps. Improve alert quality and detection coverage. 3. Incident Response Investigate and support response to incidents including: Malware and ransomware Account compromise Phishing and business email compromise Credential attacks Privilege escalation Lateral movement Suspicious PowerShell/scripts Command-and-control activity Cloud security incidents Data-exfiltration activity The engineer should be able to understand what happened, how it happened, what is affected and what needs to be done next . 4. Threat Hunting Conduct proactive threat hunting using: MITRE ATT&CK IOCs and TTPs Suspicious processes Authentication anomalies PowerShell/script activity C2 indicators Credential abuse Cloud activity Identify threats that may not have been detected through existing alerts. 5. Detection Engineering Develop and improve SIEM detection rules. Create and tune correlation rules. Develop behavioral and IOC-based detections. Map detections to MITRE ATT&CK . Identify detection gaps and improve coverage. Convert incident learnings into new detection use cases. Knowledge of Sigma is preferred. 6. EDR/XDR Investigation Analyze processes, process trees, files, hashes and network connections. Investigate endpoint behavior and persistence mechanisms. …