Monitor and investigate security alerts across SIEM and EDR platforms, analyze logs and phishing or malware activity, classify true and false positives, and respond to incidents using established playbooks. Escalate high-severity incidents, support vulnerability assessments and remediation tracking, maintain SOC documentation, apply threat intelligence, meet SOC SLAs, and assist with baseline security reviews and security configuration gap analysis.
Position: SOC L2 engineer
(3 to 5 years of experience)
Type: Full Time Employee (FTE)
Roles and Responsibilities:
o Header and sender analysis
o URL and attachment inspection
o Identification of credential-harvesting and malware delivery attempts
Technology skills and Competencies:
Certifications:
Qualifications and experience:
(3 to 5 years of experience)
Type: Full Time Employee (FTE)
Roles and Responsibilities:
- Monitor and analyze security alerts generated by SIEM platforms including Elastic SIEM, Microsoft Sentinel, and other SIEM tools (e.g., Wazuh, Splunk, QRadar).
- Perform continuous security monitoring of network traffic, endpoint activity, and system logs to identify suspicious or malicious behavior.
- Investigate potential security incidents by performing detailed log analysis to detect anomalies and attack patterns.
- Classify security alerts accurately as True Positive or False Positive based on evidence and analysis.
- Respond to security incidents promptly by following defined incident response playbooks and SOPs.
- Escalate confirmed or high-severity incidents to senior SOC engineers with proper documentation, context, and impact analysis.
- Conduct phishing email analysis, including:
o Header and sender analysis
o URL and attachment inspection
o Identification of credential-harvesting and malware delivery attempts
- Track and investigate malware alerts, performing basic static and behavioral analysis using EDR telemetry and sandbox results.
- Monitor and analyze endpoint activity using EDR tools such as Sentinel One and Microsoft Defender for Endpoint.
- Support vulnerability assessment activities by reviewing scan results, validating findings, and assisting with remediation tracking.
- Maintain accurate incident reports, investigation notes, and SOC documentation.
- Follow daily threat intelligence updates and apply relevant insights to ongoing investigations.
- Adherent to SOC SLAs, escalation procedures, and operational best practices
- Support client Baseline Security Reviews by reviewing security tool configurations and documenting gaps against defined security baselines.
Technology skills and Competencies:
- Basic to intermediate understanding of networking, security, and system administration concepts.
- Knowledge of:
- Network security fundamentals
- Firewalls, IDS/IPS, and SIEM to
- Vulnerability assessment concepts and security best practices
- Familiarity with Windows and/or Linux environments.
- Hands-on exposure to:
- SIEM monitoring and alert investigation
- Incident response and alert triage
- Endpoint detection and response (EDR) tools •
- Understanding of common attack techniques including phishing, malware, brute force, and credential abuse.
Certifications:
- CEH (Certified Ethical Hacker)
- Microsoft SC-200 - Security Operations Analyst
- Microsoft SC-900 or equivalent security fundamentals certification
Qualifications and experience:
- Bachelor's degree in computer science, Information Security, Information Technology, or a related field (or equivalent practical experience).
- Exposure to SOC operations
- Exposure to Cybersecurity monitoring
- Hands-on experience with SIEM tools and security alert investigation is preferred.
Wipfli Pune, Mahārāshtra, IND Office
Part of 1st Floor, Tower B, Panchshil Business Park Viman Nagar, Pune, India, 411014
Similar Jobs at Wipfli
Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Senior full-stack .NET developer responsible for designing, developing, integrating and deploying web applications. Lead technical delivery, mentor teams, implement CI/CD, unit tests, and collaborate with stakeholders. Work with .NET Core, C#, Azure, Angular, SQL and ORMs while promoting ownership, Agile practices, and strong OO design.
Top Skills:
.Net.Net CoreAi ToolsAngularAWSAzureAzure DevopsBootstrapC#CSSDi FrameworksEntity FrameworkGitMocking FrameworksMstestOrmReactSQLWeb ApiXunit
Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Lead architecture and delivery of enterprise .NET solutions: design scalable secure systems, guide development teams, engage clients, mentor engineers, and ensure successful production deployments.
Top Skills:
.Net.Net CoreAngularAsp.Net CoreAWSAzure DevopsC#Cosmos DbEntity FrameworkEntity Framework CoreGitAzureMongoDBMstestNunitOoadReactSQL ServerXunit
Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Lead and deliver full-stack .NET web projects, write and maintain code (.NET Core, C#), integrate cloud and web technologies, drive technical decisions, ensure unit testing and CI, collaborate with stakeholders and overseas teams.
Top Skills:
.Net.Net CoreAngularAWSAzureAzure DevopsBootstrapC#CSSEntity FrameworkJenkinsJqueryJSONMocking FrameworksMstestNinject (Di Frameworks)NunitOrmReactSQLTeamcityTypescriptUnit TestingWeb Api
What you need to know about the Pune Tech Scene
Once a far-out concept, AI is now a tangible force reshaping industries and economies worldwide. While its adoption will automate some roles, AI has created more jobs than it has displaced, with an expected 97 million new roles to be created in the coming years. This is especially true in cities like Pune, which is emerging as a hub for companies eager to leverage this technology to develop solutions that simplify and improve lives in sectors such as education, healthcare, finance, e-commerce and more.

