hirly

Apply with hirly

SecOps Engineer / Security Operations / SOC Engineer

INFRA360 SOLUTIONS · Gurugram, India

Upload your resume to see how well you match this job — free, in seconds, no account needed.

Your resume is used only to score it against this job. If you don't create an account, it is deleted within 24 hours.

About Infra360 Infra360 is a Managed Cloud Service Provider helping businesses build, secure and operate their cloud and technology environments across Cloud, DevOps, SRE, Security, FinOps and Managed Services . We are building our Security Operations and MDR capabilities and are looking for a hands-on SecOps Engineer to join the team. About the Role As a SecOps Engineer, you will be responsible for security monitoring, alert investigation, threat hunting, detection engineering and incident response across customer environments. This is not a traditional alert-monitoring role . We are looking for someone who can investigate security events, understand attacker behavior, identify the root cause, improve detections and support effective response. You will work across SIEM, EDR/XDR, cloud, identity, endpoint and network security telemetry . Key Responsibilities 1. Security Monitoring & Alert Investigation

  • Monitor and investigate security alerts across customer environments.
  • Perform alert triage and determine severity and business impact.
  • Correlate events across endpoint, identity, network and cloud sources.
  • Investigate suspicious activity and identify false positives.
  • Maintain accurate incident timelines and investigation documentation.
  • Work within defined security processes and customer SLAs. 2. SIEM / XDR Operations
  • Work with SIEM/XDR platforms such as Microsoft Sentinel, Microsoft Defender XDR, Wazuh, Splunk, Elastic, CrowdStrike, SentinelOne, Google SecOps or similar.
  • Analyze logs and security telemetry.
  • Develop and tune detection and correlation rules.
  • Monitor log-source health and identify visibility gaps.
  • Improve alert quality and detection coverage. 3. Incident Response Investigate and support response to incidents including:
  • Malware and ransomware
  • Account compromise
  • Phishing and business email compromise
  • Credential attacks
  • Privilege escalation
  • Lateral movement
  • Suspicious PowerShell/scripts
  • Command-and-control activity
  • Cloud security incidents
  • Data-exfiltration activity The engineer should be able to understand what happened, how it happened, what is affected and what needs to be done next . 4. Threat Hunting Conduct proactive threat hunting using: •

Mitre Att&ck

  • IOCs and TTPs
  • Suspicious processes
  • Authentication anomalies
  • PowerShell/script activity
  • C2 indicators
  • Credential abuse
  • Cloud activity Identify threats that may not have been detected through existing alerts. 5. Detection Engineering
  • Develop and improve SIEM detection rules.
  • Create and tune correlation rules.
  • Develop behavioral and IOC-based detections.
  • Map detections to

Mitre Att&ck

.

  • Identify detection gaps and improve coverage.
  • Convert incident learnings into new detection use cases.
  • Knowledge of Sigma is preferred. 6. EDR/XDR Investigation
  • Analyze processes, process trees, files, hashes and network connections.
  • Investigate endpoint behavior and persistence mechanisms.
  • Support endpoint isolation and containment.
  • Coordinate remediation with the Security & IT Operations team.
  • Validate endpoint security after remediation. 7. Cloud Security Monitoring Investigate security events across AWS, Azure and GCP . Exposure to technologies such as CloudTrail, GuardDuty, Security Hub, IAM, WAF, Microsoft Defender and cloud audit logs is preferred. The role focuses on security monitoring and investigation , while cloud infrastructure ownership remains with DevOps/SRE. 8. Security Automation Automate repetitive SOC activities using Python, PowerShell, APIs, SIEM automation or SOAR platforms . Examples include IOC enrichment, reputation checks, automated ticket creation, alert enrichment and response actions. 9. Threat Intelligence & Vulnerability Analysis
  • Enrich investigations using threat intelligence.
  • Analyze IPs, domains, hashes and malware indicators.
  • Track relevant CVEs and exploitation activity.
  • Support risk-based vulnerability prioritization.
  • Use threat intelligence to improve detections and investigations. What We're Looking For Must Have:
  • 3–7 years of experience in SOC, SecOps, MDR, Incident Response or Cybersecurity .
  • Strong hands-on SIEM experience.
  • Experience with EDR/XDR platforms.
  • Experience investigating security incidents.
  • Strong networking fundamentals.
  • Good Windows and Linux security knowledge.
  • Understanding of IAM and authentication.
  • Understanding of common attack techniques.
  • Incident-response experience.
  • Good understanding of

Mitre Att&ck

.

  • Strong analytical and troubleshooting skills. Good to Have:
  • MDR/MSSP experience.
  • Threat hunting experience.
  • Detection engineering.
  • Sigma/YARA knowledge.
  • Python or scripting.
  • AWS/Azure/GCP security experience.
  • Kubernetes/container security exposure.
  • SOAR experience.
  • Experience handling multiple customers or tenants. What Success Looks Like In this role, success means being able to detect, investigate and respond to security threats effectively , while continuously improving Infra360's MDR capabilities. You will contribute to better detection coverage, faster response, fewer false positives, stronger threat hunting and more effective security operations across customer environments.