The posting, in Nasuni's own words
archived Oct 9, 2026Associate Security Operations Analyst (SecOps) Location: Hyderabad (IIC) – Hybrid (3 days onsite)
Role Overview
Nasuni is seeking a Security Analyst for our global Security Operations Center. You will help protect users, identities, endpoints, cloud services, email, and collaboration platforms through first-line monitoring, evidence collection, escalation, and response support.This early-career role suits someone with practical security exposure from work, an internship, apprenticeship, or structured projects who wants to grow in a production SOC. It is not an architecture or incident-leadership role.
Read the full posting ↓
Responsibilities
Monitor and acknowledge alerts across SIEM, EDR, email, identity, cloud, and collaboration platforms. Perform first-line triage using documented playbooks, approved queries, and available user, asset, and business context. Gather logs and context; identify facts, unknowns, and affected users or systems. Analyze phishing, suspicious sign-ins, malware, credential misuse, mailbox-rule changes, endpoint anomalies, and cloud activity; escalate exceptions. Document timelines, evidence, actions, approvals, and shift handoffs so another analyst can continue the work. Execute pre-approved response and evidence-preservation steps under senior direction; do not take disruptive containment action without authorization. Label false positives, run test cases, join guided hunts, and suggest improvements. Check telemetry, validate partner findings, update runbooks, and join case reviews. Use approved AI for bounded tasks; validate outputs and protect sensitive information.
Must-Have
Practical monitoring or alert-analysis exposure through work, internship, apprenticeship, academic work, or labs. Familiarity with a SIEM or log platform and endpoint, email, identity, or cloud security. Ability to follow playbooks, interpret basic logs, gather context, and know when to close or escalate. Foundational knowledge of networking, authentication, Windows or Linux, and cloud concepts. Clear communication, careful documentation, curiosity, and willingness to seek help. Willingness to support global coverage, on-call rotations after training, and occasional after-hours work.
Preferred
Production or internship experience in an enterprise or managed SOC. Exposure to Microsoft Entra ID, Microsoft 365, AWS, Azure, or GCP security monitoring. Phishing or email-header analysis and basic KQL, SPL, or similar log-search syntax. Familiarity with case management, SOAR, MDR, MITRE ATT&CK, Python, or PowerShell.
Ideal
Independent triage of common alerts within a playbook, with appropriate escalation. Guided experience with detection testing, threat hunting, telemetry validation, or runbook improvement. Responsible AI use, including output validation and safe data handling. Security+, CySA+, SC-200, BTL1, or comparable certification completed or in progress.