HirePortal

Cyber Security Analyst L2

Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO) is a leading technology services and consulting company focused on building innovative solutions that address clients’ most complex digital transformation needs. Leveraging our holistic portfolio of capabilities in consulting, design, engineering, and operations, we help clients realize their boldest ambitions and build future-ready, sustainable businesses. With over 230,000 employees and business partners across 65 countries, we deliver on the promise of helping our customers, colleagues, and communities thrive in an ever-changing world. For additional information, visit us at www.wipro.com.

Job Description

Role Purpose

The purpose of this role is to develop and test software modules based on client requirements and prepare project documentation while coordinating with cross-functional teams to ensure quality delivery.

͏

Areas of responsibility

͏

Gathering of requirements-Assist in conducting workshops and discussions with client stakeholders to gather business process requirements.

Coding and Configuration-"Develop and deliver code for assigned modules, in alignment with client requirements ensuring proper integration with system components.

͏

Testing and Trial Runs-"Execute testing for assigned modules, validate functionality across required interactions, and participate in User Acceptance Testing (UAT) sessions.

Implementation-Participate in implementation of software application and its integration with other systems to ensure stability.

Maintain Documentation-Prepare detailed reports and documentation on project specifications, activities, and status, while presenting information using flowcharts, layouts, diagrams, code comments, and clear, well-structured code.

͏

Stakeholder Collaboration-Collaborate with cross functional teams to understand requirements, support development activities, check system compatibility, and ensure solutions meet expected standards.

SOC Analyst – Level 2 (Microsoft Security Stack)

Key Responsibilities

Threat Detection & Incident Response

  • Act as the primary escalation point for L1 SOC analysts for complex and high-severity security incidents
  • Perform advanced triage, investigation, and root cause analysis of security alerts and incidents
  • Conduct deep-dive analysis of security events, correlating data across multiple sources to identify threats
  • Execute incident containment, eradication, and recovery procedures in accordance with established playbooks and IR frameworks
  • Document incidents thoroughly, including timeline, impact assessment, remediation steps, and lessons learned
  • Participate in on-call rotations for after-hours incident response

Microsoft Azure Sentinel (Microsoft Sentinel)

  • Develop, tune, and optimize KQL (Kusto Query Language) queries for threat detection and hunting
  • Create, manage, and fine-tune analytic rules, workbooks, and dashboards in Microsoft Sentinel
  • Design and implement SOAR playbooks using Logic Apps for automated incident response
  • Configure and manage data connectors to ingest logs from diverse sources (Azure, on-premises, third-party)
  • Develop and maintain custom hunting queries and threat intelligence integrations
  • Perform regular tuning to reduce false positives and improve detection accuracy
  • Create and maintain Sentinel Workbooks for reporting and visualization

Microsoft Defender Suite

  • Monitor, investigate, and respond to alerts from:
  • Microsoft Defender for Endpoint (MDE) – Endpoint detection, advanced hunting, live response
  • Microsoft Defender for Office 365 – Email security, phishing analysis, Safe Links/Attachments
  • Microsoft Defender for Identity – Identity-based threat detection, lateral movement analysis
  • Microsoft Defender for Cloud Apps (MCAS) – Shadow IT discovery, cloud app security policies
  • Microsoft Defender for Cloud – Cloud workload protection, security posture management
  • Manage Automated Investigation and Response (AIR) capabilities
  • Perform advanced hunting using KQL across Microsoft 365 Defender portal
  • Manage attack surface reduction (ASR) rules and endpoint security policies

Azure & Cloud Security

  • Monitor and respond to security events in Microsoft Defender for Cloud (formerly Azure Security Center)
  • Assess and remediate Azure Secure Score recommendations
  • Investigate alerts related to Azure AD / Entra ID – risky sign-ins, impossible travel, identity protection
  • Monitor Conditional Access policies, MFA events, and privileged identity management (PIM) alerts
  • Support security for Azure resources including VMs, Storage Accounts, Key Vaults, NSGs, and Azure Firewall
  • Review and analyze Azure Activity Logs, Diagnostic Logs, and NSG Flow Logs

Threat Hunting & Intelligence

  • Conduct proactive threat hunting to identify advanced persistent threats (APTs) and unknown threats
  • Leverage MITRE ATT&CK framework to map adversary TTPs and improve detection coverage
  • Integrate and operationalize threat intelligence feeds within Microsoft Sentinel
  • Research emerging threats, vulnerabilities, and attack vectors relevant to the organization
  • Create threat hunting hypotheses and execute structured hunting campaigns

Process Improvement & Mentorship

  • Mentor and guide L1 analysts, providing training on investigation techniques and tools
  • Develop and update SOC playbooks, runbooks, and standard operating procedures (SOPs)
  • Identify gaps in detection and recommend improvements to security monitoring
  • Participate in purple team exercises and tabletop simulations
  • Provide detailed shift handover reports and maintain incident documentation
  • Contribute to post-incident reviews and drive remediation tracking

Reporting & Compliance

  • Generate weekly/monthly SOC metrics and KPI reports for management
  • Support audit and compliance requirements (ISO 27001, SOC 2, NIST, GDPR, HIPAA, etc.)
  • Maintain accurate records in ticketing/ITSM tools (ServiceNow, Jira, etc.)
  • Present findings and recommendations to technical and non-technical stakeholders

Required Skills & Qualifications

Technical Skills

  • 3–6 years of experience in a Security Operations Center (SOC) or cybersecurity role with at least 1–2 years at L2 level
  • Strong hands-on experience with Microsoft Sentinel – analytics rules, workbooks, playbooks, data connectors, and hunting
  • Proficiency in KQL (Kusto Query Language) – writing complex queries for detection and investigation
  • Expert-level knowledge of Microsoft Defender for Endpoint, Office 365, Identity, and Cloud Apps
  • Strong understanding of Microsoft Defender for Cloud and Azure security services
  • In-depth knowledge of Azure Active Directory / Microsoft Entra ID security features (Conditional Access, PIM, Identity Protection)
  • Solid understanding of network protocols (TCP/IP, DNS, HTTP/S, SMTP, SMB), firewall logs, and packet analysis
  • Experience with email security analysis – header analysis, phishing investigation, malware triage
  • Familiarity with SIEM/SOAR concepts, log management, and event correlation
  • Understanding of malware analysis fundamentals – static/dynamic analysis, sandboxing
  • Knowledge of Windows and Linux operating systems, event logs, and security hardening
  • Experience with PowerShell scripting for automation and investigation

Frameworks & Methodologies

  • Strong understanding of MITRE ATT&CK, Cyber Kill Chain.
  • Knowledge of OWASP Top 10 and common web application vulnerabilities
  • Understanding of Zero Trust architecture principles

Soft Skills

  • Excellent analytical thinking and problem-solving abilities
  • Strong communication skills – ability to articulate complex technical findings to diverse audiences
  • Ability to work under pressure and manage multiple incidents simultaneously
  • Strong attention to detail and documentation skills
  • Team player with a collaborative mindset
  • Self-motivated with a continuous learning attitude

Preferred / Good-to-Have Skills

  • Experience with Microsoft Copilot for Security
  • Familiarity with Azure Logic Apps / Power Automate for SOAR automation
  • Experience with additional SIEM tools (Splunk, QRadar, Chronicle)
  • Knowledge of cloud security for multi-cloud environments (AWS, GCP)
  • Experience with vulnerability management tools (Qualys, Tenable, Rapid7)
  • Familiarity with EDR/XDR platforms beyond Microsoft (CrowdStrike, SentinelOne, Carbon Black)
  • Understanding of DevSecOps principles and CI/CD pipeline security
  • Experience with digital forensics and incident response (DFIR)
  • Knowledge of scripting languages – Python, PowerShell, Bash
  • Familiarity with ITSM tools – ServiceNow, Jira Service Management

Certifications (Preferred)

Certification

Issuing Body

SC-200: Microsoft Security Operations Analyst

Microsoft

SC-900: Microsoft Security, Compliance, and Identity Fundamentals

Microsoft

AZ-500: Microsoft Azure Security Technologies

Microsoft

MS-500: Microsoft 365 Security Administration

Microsoft

CompTIA CySA+

CompTIA

CompTIA Security+

CompTIA

CEH – Certified Ethical Hacker

EC-Council

Mandatory Skills: Cloud Security Engineering .Experience: 3-5 Years .Reinvent your world. We are building a modern Wipro. We are an end-to-end digital transformation partner with the boldest ambitions. To realize them, we need people inspired by reinvention. Of yourself, your career, and your skills. We want to see the constant evolution of our business and our industry. It has always been in our DNA - as the world around us changes, so do we. Join a business powered by purpose and a place that empowers you to design your own reinvention.

Skills

  • SIEM
  • Incident Response
  • Threat Analysis
  • Network Security
  • Vulnerability Management
  • Security Operations
  • Splunk

Related jobs

Wipro LimitedApply for this job