SIEM L1 Analyst
Persistent Systems · Security DU6
Apply ↗Skills
["SIEM Management""Penetration testing""Incident Management""Security"]Technology stack
{}Description
Job Title: SIEM Level 1 Analyst Location: Pune Experience: 1–2 years in IT or cybersecurity (freshers with training may be considered) Role Summary: As a SIEM L1 Analyst, you will be the first line of defense in the Security Operations Center (SOC), responsible for monitoring, triaging, and escalating security alerts generated by the SIEM platform. You will ensure timely detection of potential threats and maintain accurate documentation of incidents. Key Responsibilities: Security Monitoring: Monitor real-time alerts and dashboards from SIEM tools (e.g., Splunk). Identify and classify security events based on severity and impact. Alert Triage & Escalation: Perform initial analysis of alerts to determine legitimacy. Escalate confirmed or suspicious incidents to L2 analysts with relevant context. Log Review & Analysis: Review logs from firewalls, IDS/IPS, antivirus, and endpoint protection systems. Correlate events across multiple data sources to identify patterns. Incident Documentation: Maintain detailed records of alerts, investigations, and actions taken. Ensure incident tickets are updated and closed in a timely manner. Tool Usage & Maintenance: Use ticketing systems (e.g., ServiceNow, JIRA) to track incidents. Assist in basic SIEM maintenance tasks like health checks and log ingestion validation. Threat Intelligence Support: Reference threat feeds and known IOCs to validate alerts. Tag and categorize incidents based on threat type and source. Shift Operations: Work in rotational shifts to ensure 24/7 SOC coverage. Participate in daily SOC briefings and handovers. Compliance & Policy Adherence: Follow organizational security policies and incident handling procedures. Support audit and compliance efforts with accurate data logging. Required Skills: Basic understanding of cybersecurity concepts and threat types Familiarity with SIEM platforms (Splunk, QRadar, Sentinel, etc.) Knowledge and good understanding on end point security Microsoft Defender Knowledge of Windows/Linux logs, networking basics, and common attack vectors Strong analytical and communication skills Ability to work in a fast-paced, team-oriented environment Preferred Certifications: CompTIA Security+, Microsoft SC-200, or equivalent SIEM-specific training or certification (e.g., Splunk Fundamentals)
Requirements
["SIEM Management", "Penetration testing", "Incident Management", "Security"]
Roles & responsibilities
[]
About