Apply with hirly
SecOps Engineer / Security Operations / SOC Engineer
INFRA360 SOLUTIONS · Gurugram, India
Upload your resume to see how well you match this job — free, in seconds, no account needed.
Your resume is used only to score it against this job. If you don't create an account, it is deleted within 24 hours.
About Infra360 Infra360 is a Managed Cloud Service Provider helping businesses build, secure and operate their cloud and technology environments across Cloud, DevOps, SRE, Security, FinOps and Managed Services . We are building our Security Operations and MDR capabilities and are looking for a hands-on SecOps Engineer to join the team. About the Role As a SecOps Engineer, you will be responsible for security monitoring, alert investigation, threat hunting, detection engineering and incident response across customer environments. This is not a traditional alert-monitoring role . We are looking for someone who can investigate security events, understand attacker behavior, identify the root cause, improve detections and support effective response. You will work across SIEM, EDR/XDR, cloud, identity, endpoint and network security telemetry . Key Responsibilities 1. Security Monitoring & Alert Investigation
- Monitor and investigate security alerts across customer environments.
- Perform alert triage and determine severity and business impact.
- Correlate events across endpoint, identity, network and cloud sources.
- Investigate suspicious activity and identify false positives.
- Maintain accurate incident timelines and investigation documentation.
- Work within defined security processes and customer SLAs. 2. SIEM / XDR Operations
- Work with SIEM/XDR platforms such as Microsoft Sentinel, Microsoft Defender XDR, Wazuh, Splunk, Elastic, CrowdStrike, SentinelOne, Google SecOps or similar.
- Analyze logs and security telemetry.
- Develop and tune detection and correlation rules.
- Monitor log-source health and identify visibility gaps.
- Improve alert quality and detection coverage. 3. Incident Response Investigate and support response to incidents including:
- Malware and ransomware
- Account compromise
- Phishing and business email compromise
- Credential attacks
- Privilege escalation
- Lateral movement
- Suspicious PowerShell/scripts
- Command-and-control activity
- Cloud security incidents
- Data-exfiltration activity The engineer should be able to understand what happened, how it happened, what is affected and what needs to be done next . 4. Threat Hunting Conduct proactive threat hunting using: •
Mitre Att&ck
- IOCs and TTPs
- Suspicious processes
- Authentication anomalies
- PowerShell/script activity
- C2 indicators
- Credential abuse
- Cloud activity Identify threats that may not have been detected through existing alerts. 5. Detection Engineering
- Develop and improve SIEM detection rules.
- Create and tune correlation rules.
- Develop behavioral and IOC-based detections.
- Map detections to
Mitre Att&ck
.
- Identify detection gaps and improve coverage.
- Convert incident learnings into new detection use cases.
- Knowledge of Sigma is preferred. 6. EDR/XDR Investigation
- Analyze processes, process trees, files, hashes and network connections.
- Investigate endpoint behavior and persistence mechanisms.
- Support endpoint isolation and containment.
- Coordinate remediation with the Security & IT Operations team.
- Validate endpoint security after remediation. 7. Cloud Security Monitoring Investigate security events across AWS, Azure and GCP . Exposure to technologies such as CloudTrail, GuardDuty, Security Hub, IAM, WAF, Microsoft Defender and cloud audit logs is preferred. The role focuses on security monitoring and investigation , while cloud infrastructure ownership remains with DevOps/SRE. 8. Security Automation Automate repetitive SOC activities using Python, PowerShell, APIs, SIEM automation or SOAR platforms . Examples include IOC enrichment, reputation checks, automated ticket creation, alert enrichment and response actions. 9. Threat Intelligence & Vulnerability Analysis
- Enrich investigations using threat intelligence.
- Analyze IPs, domains, hashes and malware indicators.
- Track relevant CVEs and exploitation activity.
- Support risk-based vulnerability prioritization.
- Use threat intelligence to improve detections and investigations. What We're Looking For Must Have:
- 3–7 years of experience in SOC, SecOps, MDR, Incident Response or Cybersecurity .
- Strong hands-on SIEM experience.
- Experience with EDR/XDR platforms.
- Experience investigating security incidents.
- Strong networking fundamentals.
- Good Windows and Linux security knowledge.
- Understanding of IAM and authentication.
- Understanding of common attack techniques.
- Incident-response experience.
- Good understanding of
Mitre Att&ck
.
- Strong analytical and troubleshooting skills. Good to Have:
- MDR/MSSP experience.
- Threat hunting experience.
- Detection engineering.
- Sigma/YARA knowledge.
- Python or scripting.
- AWS/Azure/GCP security experience.
- Kubernetes/container security exposure.
- SOAR experience.
- Experience handling multiple customers or tenants. What Success Looks Like In this role, success means being able to detect, investigate and respond to security threats effectively , while continuously improving Infra360's MDR capabilities. You will contribute to better detection coverage, faster response, fewer false positives, stronger threat hunting and more effective security operations across customer environments.