Lead - Captive Operations
Tata Communications
Tata Communications Redefines Connectivity with Innovation and IntelligenceDriving the next level of intelligence powered by Cloud, Mobility, Internet of Things, Collaboration, Security, Media services and Network services, we at Tata Communications are envisaging a New World of Communications
Job Title: NG SIEM Analyst – L2
Location: Client Location, Hyderabad
Experience Required
- Minimum 7+ years of relevant experience with BCA/BSc-IT
- Or minimum 5+ years of relevant experience with B.E./B.Tech/MCA Certifications Preferred: CEH, ArcSight Admin SIEM product certifications
We are looking for an experienced L2 NG SIEM Analyst to support the day-to-day operations of our Next-Gen SIEM environment (SIEM + SOAR + UEBA). The candidate will be responsible for monitoring dashboards, responding to alerts, performing preliminary investigations, and supporting integrations and routine operational tasks under the guidance of L3 resources.
Key Responsibilities
- Monitor NG SIEM (SIEM + SOAR + UEBA) consoles, dashboards, and alerts; provide timely responses to security incidents.
- Assist in incident triage, classification, and escalation to L3 team based on severity.
- Perform preliminary analysis of security events and provide recommendations for closure or mitigation.
- Support the integration of log sources such as firewalls, endpoint security tools, AD, WAF, antivirus, patch management tools, ERP systems, and custom applications.
- Monitor health status of system components and raise issues to L3 team when necessary.
- Assist in the creation and fine-tuning of use cases/playbooks/reports and alert rules under the guidance of the L3 team.
- Support custom parser and connector development in collaboration with the L3 team.
- Work with L3 team on reducing false positives by reviewing correlation rules and configurations.
- Follow Standard Operating Procedures (SOPs) and assist in documentation updates.
- Support the onboarding of new log sources and data validation post-integration.
- Provide timely support for access-related requests and permissions within the NG SIEM solution.
- Perform routine tasks such as backup monitoring, report generation, and compliance checks.
- Participate in Cyber Drills and tabletop exercises as part of continuous learning and SOC readiness.
- Maintain audit and incident logs as per company policy and assist during audits with required data and documentation.
- Stay updated on cyber threat trends and assist in implementing recommendations for improved detection and response.
- Escalate unresolved technical issues to the L3 team and support troubleshooting under guidance.
- Strong working knowledge of at least one NG SIEM platform (ArcSight).
- Familiarity with SOAR and UEBA concepts and basic operational understanding.
- Basic experience in writing and managing correlation rules, alerts, and queries.
- Understanding of threat intelligence and incident response lifecycle.
- Familiarity with MITRE ATT&CK and NIST frameworks.
- Hands-on experience with security logs from Windows/Linux servers, network devices, security appliances, and cloud infrastructure.
- Working knowledge of scripting or regex is a plus.
- Good analytical, documentation, and communication skills.
- Excellent problem-solving and troubleshooting skills.
- Ability to work under pressure and meet deadlines.
- Strong team collaboration and willingness to learn from senior team members.
- Strong communication and incident documentation/reporting ability.