Fonada
Website:
fonada.com
Job details:
Company: Fonada / Shivtel Communications Pvt. Ltd.
Job Title: Senior SOC Analyst
Department: Information Security / Cyber Security
Experience: 5+ Years
Location: Noida
Employment Type: Full-Time
About Fonada
Fonada is a leading AI-powered CPaaS platform helping enterprises transform customer communication through Voice, SMS, WhatsApp Business API, Contact Center, IVR, AI Voice Bots, Chatbots, and Conversational AI solutions. We are committed to building secure, scalable, and reliable communication platforms for businesses across industries.
About the Role
We are looking for an experienced Senior SOC Analyst to join our Cyber Security team. The role will be responsible for monitoring security events, investigating and responding to incidents, performing threat detection and hunting, and strengthening the organization's security posture.
The ideal candidate should have strong hands-on experience with SOC Operations, Incident Response, SIEM, EDR/XDR, Cloud Security, threat intelligence, and security investigations. The candidate should be comfortable handling incidents independently and demonstrating strong analytical and technical troubleshooting skills.
Key Responsibilities
- Monitor and analyze security alerts from SIEM, EDR/XDR, WAF, Firewall, Email Security and Cloud Security platforms.
- Perform end-to-end incident detection, investigation, containment, eradication and recovery.
- Investigate security incidents involving malware, phishing, account compromise, credential theft, suspicious endpoint activity and unauthorized access.
- Analyze Windows Security Events, authentication logs, network traffic, email headers and other security telemetry.
- Conduct threat hunting to identify suspicious activities and potential indicators of compromise.
- Develop and optimize SIEM detection rules, correlation rules and queries to improve detection accuracy and reduce false positives.
- Write and analyze Splunk SPL queries for security investigations and threat detection.
- Investigate suspicious PowerShell, command-line and process execution activity using EDR/XDR tools.
- Analyze MITRE ATT&CK techniques and map observed attacker behavior to relevant tactics and techniques.
- Investigate phishing campaigns using SPF, DKIM and DMARC results, email headers and sender infrastructure.
- Investigate suspicious sign-ins and account compromise in Microsoft Entra ID / Azure AD, including session and credential-related activity.
- Analyze WAF and firewall events to identify DDoS, brute-force and credential-stuffing attacks.
- Support vulnerability and CVE assessment, including prioritization based on CVSS and environmental/business context.
- Coordinate with IT, Infrastructure, Network, Cloud and Application teams during security incidents.
- Prepare detailed incident reports, investigation findings, root-cause analysis and remediation recommendations.
- Maintain accurate incident documentation, evidence and SOC operational records.
- Participate in continuous improvement of SOC processes, playbooks and security monitoring capabilities.
Required Skills & Technical Expertise
- SIEM: Splunk or equivalent SIEM platforms
- EDR/XDR: CrowdStrike, Microsoft Defender for Endpoint or equivalent
- Identity & Cloud: Microsoft Entra ID / Azure AD and cloud security concepts
- Strong understanding of Windows Security Events, authentication and endpoint telemetry
- Strong knowledge of Incident Response and SOC Operations
- Knowledge of MITRE ATT&CK Framework
- Working knowledge of SPF, DKIM and DMARC
- Experience analyzing email headers and phishing attacks
- Knowledge of WAF, Firewall, DDoS, brute-force and credential-stuffing attacks
- Strong understanding of IOC/IOA, threat intelligence and threat hunting
- Experience with Splunk SPL / SIEM query development
- Understanding of CVE, CVSS and vulnerability management
- Knowledge of cybersecurity frameworks, standards and security best practices
- Strong analytical and problem-solving skills
Key Competencies
- Incident investigation and response
- Threat detection and hunting
- Log and security event analysis
- Security alert triage
- Root-cause analysis
- Detection engineering
- Risk assessment
- Technical documentation and reporting
- Cross-functional coordination
- Ability to work effectively in a 24ร7 SOC environment, if required
Education & Experience
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology or a related field.
- 5+ years of hands-on experience in SOC Operations, Security Operations, Incident Response or Cybersecurity.
- Relevant certifications such as CEH, CompTIA Security+, CySA+, GCIH, GCIA, CISSP, SC-200 or equivalent will be an advantage.
What We Are Looking For
The candidate should be able to demonstrate practical investigation skills rather than only theoretical cybersecurity knowledge. Experience should include handling real-world security scenarios, writing SIEM queries, analyzing logs and headers, investigating endpoint behavior, identifying attack techniques and coordinating appropriate containment and remediation.
The assessment for this role specifically covers fundamentals, technical depth, scenario-based investigation, and hands-on query/log/header analysis, including phishing and account compromise, EDR investigations, WAF/DDoS analysis, Splunk SPL, email authentication and CVE validation.
Click on Apply to know more.