Mid SOC Analyst
Wrike · Bangalore
Free to search · AI fit score against your CV · tailor your résumé in one click
Wrike · Bangalore
Wrike is the most powerful work management platform. Built for teams and organizations looking to collaborate, create, and exceed every day, Wrike brings everyone and all work into a single place to remove complexity, increase productivity, and free people up to focus on their most purposeful work. Wrike is our people, not a place. As a distributed team, we own our growth, stay globally connected, and rely on the product we build to deliver impactful work alongside brilliant minds. You'll have real ownership over meaningful work, a global team that has your back, and the flexibility to do your best work your way. If that sounds like you, we'd love to hear from you. Our vision: A world where everyone is free to focus on their most purposeful work, together. About the Role: With flexible, distributed-first ways of working, you'll have the support to do your best work, wherever you are. Wrike commits to its customers that their data is monitored around the clock. Our Security Operations Center delivers on that promise through a hybrid model with a 24/7 managed detection partner (Rapid7)—and our analysts are the core drivers who handle escalations, conduct deep-dive investigations, and execute immediate action. As an L2 SOC Analyst, you will play a pivotal role in our security rotation: monitoring and triaging security alerts, responding to escalations from our MDR partner, investigating incidents end-to-end, and continuously maturing our detection capabilities to protect Wrike and our customers. Your Impact: • Alert Triage & Escalation: Monitor, triage, and investigate security alerts and events, including direct escalations from our 24/7 MDR partner (Rapid7). • Incident Containment & Forensics: Assess risk and impact of potential incidents, conducting end-to-end investigations (log analysis, endpoint forensics, scoping) and taking swift remediation actions. • On-Call Coverage: Participate in the SOC on-call rotation to guarantee round-the-clock escalation coverage. • Detection Engineering & Tuning: Continuously refine and tune detection rules to minimize false positives and identify genuine threats faster. • Proactive Threat Hunting: Contribute to threat hunting initiatives across endpoints, identity providers, SaaS platforms, and cloud environments. • Process Improvement: Help document, refine, and optimize SOC playbooks, runbooks, incident reports, and operational escalation workflows. Your Qualifications: • Experience: 2–3+ years of hands-on experience in a SOC or security monitoring environment (alert triage, incident investigation, and response). • Technical Proficiency: Hands-on experience with SIEM platforms (Rapid7 InsightIDR or similar) and EDR/antimalware tooling for endpoint investigations. • Core Knowledge: Strong understanding of network security fundamentals, common threat vectors, and attack frameworks (MITRE ATT&CK). • Problem-Solving & Communication: Sharp logical thinking and analytical skills paired with advanced written and verbal English communication abilities. • Availability: Ability and willingness to participate in an on-call rotation, including occasional nights and weekends. Standout Qualities: • Hybrid Model Experience: Prior experience collaborating directly with an MDR or MSSP partner in a hybrid SOC environment. • Extended Tooling Expertise: Hands-on familiarity with tools such as Splunk, Wazuh, Microsoft Defender for Endpoint, Crowdtrike, Okta, Google Workspace, AWS, or GCP. • Advanced Capabilities: Previous experience in active threat hunting, detection engineering, or task automation using Python/Bash. • Industry Certifications: Relevant security certifications (e.g., Security+, CySA+, GCIH, GCDA, or vendor-specific certifications). Team Dynamics: You will join a highly collaborative, vigilant, and supportive Security Operations Center team. In this role, you will work closely with internal incident responders, cross-functional IT and infrastructure teams, and directly alongside analysts from our 24/7 MDR partner (Rapid7). The team culture values transparent communication, continuous learning, and collective ownership of security outcomes. Our Work Style: We operate in a dynamic, hybrid security model utilizing modern cloud-first security tooling. • Tech Stack & Tools: Rapid7 InsightIDR, EDR/XDR platforms, Okta, Google Workspace, AWS/GCP, and custom Python/Bash automation scripts. • Methodologies: Framework-driven incident response aligned with MITRE ATT&CK, structured playbooks, and continuous threat-hunting cycles. • What Makes Us Different: Unlike traditional SOC environments burdened by endless repetitive alerts, our hybrid model leverages an MDR partner to offload initial noise. This allows our L2 Analysts to focus on complex investigations, high-impact threat hunting, and genuine detection engineering. Benefits & Perks: • 18 calendar days of paid vacation • 12 days of National & Festival holidays (10 fixed, 2 flexible) • Sick Leave Compensation (5 Paid Uncertified Sick Days) • Menstrual Leave: Twelve (12) days per calendar year. Women employees are eligible for up to 1 day of m