Jobs Companies Revantage SOC Analyst — Security Operations

À propos de ce poste SOC Analyst — Security Operations chez Revantage

Revantage · Sur site · Bengaluru

ESSENTIAL JOB DUTIES

1.  Alert Monitoring & Initial Triage

  • Monitor the security alert queue continuously across shift, ensuring no alerts are missed, delayed, or left without an initial disposition.
  • Perform initial triage of incoming alerts: review alert context, classify by type and potential severity, and determine whether the alert warrants escalation or closure as a false positive.
  • Apply documented playbooks and runbooks to guide triage decisions; escalate promptly to L2 when an alert exceeds L1 scope or confidence threshold.
  • Maintain accurate, timely documentation of all triage actions: alert details, initial findings, disposition rationale, and escalation notes.
  • Support shift handoff quality by ensuring all open items are clearly documented and communicated to the incoming analyst.

2.  ReliaQuest GreyMatter

  • Use GreyMatter as the primary platform for alert review, case management, and initial investigation workflows.
  • Navigate GreyMatter case queues, apply filters, and use built-in enrichment and AI-assisted features to support triage decisions — always validating outputs before acting.
  • Document findings, disposition notes, and escalation rationale within GreyMatter case records in accordance with SOC documentation standards.
  • Develop proficiency with GreyMatter investigation workflows through structured on-the-job learning and guidance from L2 analysts and the SOC Manager.

3.  Microsoft Defender for Endpoint

  • Review MDE alerts surfaced through GreyMatter or the MDE portal; understand alert categories, severity levels, and associated device context.
  • Perform basic endpoint investigation tasks: review device timelines for obvious indicators, check process trees, and identify key artifacts to include in escalation notes.
  • Understand and apply MDE alert triage criteria to support accurate initial severity classification.

4.  Microsoft Sentinel

  • Review Sentinel incidents and alerts as part of the monitoring queue; understand alert sources and the log types that feed detections.
  • Run basic KQL queries using provided templates to retrieve log evidence and support initial triage findings.
  • Develop foundational KQL proficiency over time, progressing toward independent query construction for common triage scenarios.

5.  SSE/SWG Platforms — Zscaler & Netskope

  • Develop working familiarity with Zscaler and Netskope alert types, log sources, and basic policy constructs.
  • Review web security alerts and support L2 analysts with initial context gathering for Zscaler and Netskope-related investigations.
  • Follow documented workflows for reporting and escalating SSE/SWG events that exceed L1 triage capability.

6.  ServiceNow Ticket Handling

  • Manage ServiceNow tickets assigned to the InfoSec/SOC queue: acknowledge, classify, document, and escalate or resolve within SLA.
  • Handle routine, low-complexity security tickets: user-reported suspicious emails, access queries, and basic security tool questions — following documented resolution procedures.
  • Maintain accurate ticket records: classification, evidence summary, actions taken, and resolution notes aligned to SOC documentation standards.
  • Flag repeat patterns or unresolved issues for L2 review and knowledge article creation.

7.  Email Security

  • Perform initial triage of user-reported phishing and suspicious email submissions using Mimecast and/or Abnormal.ai.
  • Apply documented phishing triage criteria: assess sender, links, attachments, and headers; classify and escalate confirmed or suspected malicious emails to L2.
  • Support quarantine and release workflows under L2 direction; document findings and outcomes in the relevant ticket or case record.

REQUIRED SKILLS & EXPERIENCE

  • 1+ years of experience in a SOC, IT operations, helpdesk, or security monitoring role.
  • Basic understanding of networking fundamentals: TCP/IP, DNS, HTTP/S, common ports and protocols.
  • Familiarity with Windows operating system concepts: processes, services, event logs, and common file system paths.
  • Awareness of common attack types and indicators: phishing, malware, credential abuse, and suspicious scripting.
  • Ability to follow structured procedures, playbooks, and escalation paths with precision and consistency.
  • ServiceNow or equivalent ITSM tool experience: ticket creation, classification, and documentation.
  • Strong attention to detail and clear written communication for ticket notes, case documentation, and shift handoffs.

PREFERRED QUALIFICATIONS

  • Prior exposure to a SIEM platform (Microsoft Sentinel, Splunk, or similar) for alert review or basic log analysis.
  • Familiarity with Microsoft Defender for Endpoint or equivalent EDR tooling.
  • Exposure to phishing analysis and email security tools (Mimecast, Abnormal.ai, or similar).
  • Understanding of the MITRE ATT&CK framework at a foundational level.
  • Experience working in a 24×7 shift environment.

EDUCATION & CERTIFICATIONS

  • Bachelor's degree in Computer Science, Information Security, Engineering, or equivalent practical experience.
  • CompTIA Security+ — preferred or actively pursuing.
  • Microsoft SC-900 (Security, Compliance, and Identity Fundamentals) — a plus.
  • CompTIA CySA+ or equivalent — desirable as a development target.

SUCCESS MEASURES

  • SLA compliance and accurate, complete documentation for all assigned ServiceNow tickets.
  • Alert triage accuracy: low false-positive closure rate and appropriate, timely escalations to L2.
  • Shift handoff quality: all open items documented and communicated clearly with no gaps.
  • Demonstrated progression in GreyMatter proficiency and foundational tool knowledge over the first 90 days.
  • Positive contribution to team knowledge through flagging repeat patterns and supporting runbook updates.

WORKING CONDITIONS

  • 24×7 rotational shifts including nights, weekends, and holidays.
  • On-call support may be required for high-severity incidents.
  • Role demands sustained alertness, consistent process adherence, and composed, methodical work under pressure.

Job Applicant Privacy Notice

EEO Statement

The Company is an equal opportunity employer. In accordance with applicable law, we prohibit discrimination against any applicant, employee, or other covered person based on any legally recognized basis, including, but not limited to: veteran status, uniformed servicemember status, race, color, caste, immigration status, religion, religious creed (including religious dress and grooming practices), sex, gender, gender expression, gender identity, marital status, sexual orientation, pregnancy (including childbirth, lactation or related medical conditions), age, national origin or ancestry, citizenship, physical or mental disability, genetic information (including testing and characteristics), protected leave status, domestic violence victim status, or any other consideration protected by federal, state or local law. We are committed to providing reasonable accommodations, if you need an accommodation to complete the application process, please email [email protected]

Prêt à postuler chez Revantage ?
Postuler chez Revantage

À propos de Revantage

Revantage, a Blackstone Real Estate portfolio company, is a global corporate services leader headquartered in Chicago. In Pursuit of Better, the company delivers value-add services and best-in-class talent to Blackstone real estate portfolio companies and investments across asset classes including logistics, residential, office, hospitality and retail in North America, Europe, Asia, Australia and New Zealand. From Finance to Technology to Human Resources, Revantage anticipates service needs, hires exceptional talent and enables its business partners to thrive, while fostering a fun and inclusive culture for its team members.

Voir tous les emplois chez Revantage →

Emplois similaires

Moonpay
Senior SOC Analyst
Moonpay
⚡ Postuler tôt Bengaluru, Karnataka Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 4 j
Moonpay
SOC Analyst
Moonpay
⚡ Postuler tôt Bengaluru, Karnataka Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 4 j
Saviynt
SOC Analyst II
Saviynt
⚡ Postuler tôt Bengaluru Hybride
● Nouveau 👁 Vu ✓ Postulé il y a 6 j
Saviynt
AI Detection Engineer - SOC Analyst IV
Saviynt
⚡ Postuler tôt Bengaluru Hybride
● Nouveau 👁 Vu ✓ Postulé il y a 6 j
Anduril Industries
Security Operations Analyst
Anduril Industries
⚡ Postuler tôt Seattle, Washington, United St... Sur site $129,000–$171,000
● Nouveau 👁 Vu ✓ Postulé il y a 14 h
Anduril Industries
Security Operations Analyst
Anduril Industries
⚡ Postuler tôt Boston, Massachusetts, United... Sur site $129,000–$171,000
● Nouveau 👁 Vu ✓ Postulé il y a 14 h
Anduril Industries
Security Operations Analyst
Anduril Industries
⚡ Postuler tôt Costa Mesa, California, United... Sur site $129,000–$171,000
● Nouveau 👁 Vu ✓ Postulé il y a 14 h
Point Digital Finance, Inc.
Senior Security Operations Analyst (Detection & Response)
Point Digital Finance, Inc.
⚡ Postuler tôt San Francisco, California, Uni... Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 2 j
Point Digital Finance, Inc.
Senior Security Operations Analyst (Detection & Response)
Point Digital Finance, Inc.
⚡ Postuler tôt United States Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 2 j

Inscrivez-vous pour des suggestions adaptées aux emplois que vous ouvrez et aux recherches que vous enregistrez.

Plus d’emplois chez Revantage

Voir tous les emplois chez Revantage →

Postuler maintenant
🤖

Doucement — un instant

JobsRadar a été conçu pour de vraies personnes qui traversent une période difficile dans leur recherche d’emploi — pas pour des requêtes automatisées. Vous cliquez beaucoup trop vite et vous êtes maintenant temporairement bloqué.

Revenez plus tard. Si vous cherchez réellement un emploi, nous sommes de votre côté — agissez simplement comme un être humain.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Prenez une longueur d’avance dans votre recherche d’emploi.

Rejoignez notre canal Telegram pour ce qui vous aide à décrocher le poste — références salariales, le pouls hebdomadaire du marché et les annonces de nouveautés. Pas de spam, que du signal.

Rejoindre le canal — c’est gratuit