Website:
dtekmicro.com
Job details:
Company Description DTekMicro is a cybersecurity-focused organization dedicated to protecting businesses from evolving digital threats. The company operates advanced Security Operations Centers (SOCs) that provide continuous monitoring, incident response, and threat analysis for clients across industries. DTekMicro emphasizes innovation, strong analytical methodologies, and the use of cutting-edge technologies to safeguard critical infrastructure and data. Team members collaborate closely to design and implement robust security strategies that help organizations improve their resilience against cyber attacks.
Role Description The Lead L3 SOC Analyst is a full-time, on-site role based in New Delhi, responsible for overseeing complex security incidents and leading advanced investigations. In this role, the analyst will perform in-depth cyber threat hunting, analyze security alerts and logs, and correlate data across multiple tools and platforms to identify and mitigate sophisticated threats. The position involves mentoring and guiding junior SOC analysts, refining detection use cases, and collaborating with cross-functional teams to improve incident response playbooks and security posture. The Lead L3 SOC Analyst will also support cyber threat intelligence integration, conduct root cause analysis, and prepare clear incident reports and recommendations for internal stakeholders and clients.
Job Title: Lead L3 SOC Analyst
Department: Internet Security Operations Center (ISOC) Position Type: Full-Time
Position Overview
Job Location: Delhi Near Lodhi Road
Client: DTekMicro
Interview Rounds: 3
Notice Period: 15 Days
Hybrid/WFO(if WHO, number of working days) WFO /5 Days
We are seeking an expert Level 3 (L3) Security Operations Center (SOC) Analyst and Threat Hunter to serve as the technical authority for our enterprise SecOps ecosystem. In this role, you will be the final escalation point for complex security incidents spanning our internal network fabric and perimeter boundaries. Lead cyber incident investigation, threat hunting, malware analysis, security architecture improvements, and major incident response.
The ideal candidate possesses deep, hands-on experience correlation-mapping internal East-West traffic captured by NDR with North-South perimeter traffic logged through FortiAnalyzer. You will design, build, and optimize behavioral analytics models in FortiUEBA, author multi-vector correlation rules in FortiSIEM, and build fully automated containment playbooks via FortiSOAR that safely interact with FortiManager to orchestrate remote firewall defenses.
Core Responsibilities
• Advanced Incident Handling (Escalation Point): Act as the final technical tier (L3) for investigating high-severity alerts. Conduct deep-dive forensic analysis on network anomalies, data exfiltration attempts, and lateral movement.
• Network Detection & Response (NDR): Analyze raw packets, deep packet inspection (DPI) "Smart Data", and IPFIX/NetFlow streams coming exclusively from internal NetScout ISNG/AED probes to detect stealthy internal threats.
• Log Correlation & Management Strategy: Oversee the data fabric between FortiAnalyzer (North-South perimeter traffic) and FortiSIEM. Develop custom parsers, event handlers, and cross-platform correlation rules to bind edge traffic to internal network behavior.
• Behavioral Profiling (UEBA): Manage and tune FortiUEBA algorithms. Map user identity logs and access schemas against anomalous internal network activity flagged by NetScout to assign accurate entity risk scores.
• SOAR Architecture & Playbook Design: Architect, build, and maintain automated playbooks within FortiSOAR. Design logic that translates multi-vector incidents into rapid, reliable REST API actions pushed directly down to Forti Manager.
• Change-Safe Containment Orchestration: Ensure playbook actions strictly adhere to enterprise change management by utilizing FortiManager to inject address objects or policy overrides into remote FortiGate NGFWs, rather than modifying active firewalls directly.
• Threat Hunting & Detection Engineering: Proactively hunt for advanced persistent threats (APTs) hidden within internal traffic logs. Continually update the SOC’s detection engineering pipeline based on newly discovered Mitre ATT&CK techniques.
Required Technical Skills & Qualifications
• Fortinet SecOps Expertise: Minimum 3+ years of direct engineering and operational experience with FortiSIEM, FortiSOAR, and FortiAnalyzer.
• Fortinet Network Management: Deep understanding of FortiManager ADOMs (Administrative Domains), policy object structures, and staging workflows, alongside remote FortiGate policy administration.
• NetScout Mastery: Strong experience navigating NetScout Omnis / InfiniStreamNG / AED consoles to analyze flow metrics, packet captures (PCAPs), and internal boundary triggers.
• Automation & Scripting: Proficient in writing Python scripts and building REST API payloads to create seamless integration hooks between FortiSOAR and external appliances.
• Network Fundamentals: Expert-level knowledge of TCP/IP, packet analysis, Wireshark, IPFIX, NetFlow, and routing protocols.
Certifications (Highly Preferred):
• Fortinet Certified Professional / Solution Specialist in Security Operations (FCP / FCSS in SecOps) or Network Security (FCSS in Network Security).
• Industry standard certifications: GIAC (GCIA, GCIH, GNFA, GCDA) or CISSP.
Experience & Education
• Education: Bachelor’s degree in Computer Science, Cyber Security, Network Engineering, or equivalent practical enterprise experience.
• Experience: 5+ years of dedicated experience working inside an enterprise SOC, with at least 2 years operating at a Senior L3 or Detection Engineering
Click on Apply to know more.