Virtusa Recognized as Global Leader in Gen AI Services by ISG Provider Lens® - Read report

× Success! Job has been saved successfully.

Lead SoC Analyst

Colombo, Western Province, Sri Lanka
Posted on: 10-09-2025

Job description

Key responsibilities & Accountabilities:

* Advanced Incident Response & Threat Investigation
Investigate and remediate escalated security incidents involving advanced attack techniques.
Perform detailed forensic data collection, root cause analysis, and system restoration.

* Mentorship & Knowledge Sharing
Provide guidance and mentorship to L1 analysts on investigation techniques, escalation workflows, and threat
mitigation strategies.
Conduct knowledge-sharing sessions within the SOC to improve detection capabilities.

* Inter-Team Collaboration & Documentation
Work alongside IT, engineering, and compliance teams to enhance security workflows and response plans.
Develop training materials and process documentation to support cross-functional security initiatives.

* Advanced Security Stack Management & Optimization
Conduct advanced tuning of security detection tools to enhance accuracy and reduce false positives.
Address complex tuning requests escalated from L1 analysts.

* Threat Hunting & Proactive Security Analysis
Perform in-depth analysis of suspicious activities to uncover and mitigate hidden security threats.
Conduct intermediate-level threat hunting, focusing on host artifacts, domain patterns, and network anomalies.

* Intermediate Detection Engineering
Develop detection rules and mechanisms to address network and host-based threats.

* Security Tools Proficiency & Continuous Improvement
Utilize and manage SIEM, EDR, XDR, vulnerability scanners, firewalls, and email gateways at an intermediate level.

* Reporting, Documentation & Stakeholder Communication
Create detailed security reports on incidents, emerging threats, and SOC operational performance

* 24x7 SOC Operations & Leadership Support

Maintain operational readiness in a 24/7 SOC environment, ensuring effective incident management and response
during all shifts.
Act as a point of escalation for complex security events, providing guidance to junior analysts and ensuring smooth
SOC operations.
Contribute to continuous improvement efforts, refining SOC workflows and enhancing detection capabilities.

Skills & Ability

Technical Skills
Strong understanding of security frameworks, attack tactics (MITRE ATT&CK), and defensive security operations.
Proficiency in security monitoring tools (SIEM, EDR, XDR, vulnerability scanners, firewalls, IDS/IPS).
Experience with log analysis, forensic investigation techniques, and security event correlation.
Ability to analyze malicious activity across endpoints, networks, and cloud environments.

Soft Skills
Strong problem-solving skills with the ability to investigate and resolve complex security incidents.
Excellent written and verbal communication for effective documentation and reporting.
Ability to work in high-pressure environments, multitask, and adapt to evolving cybersecurity challenges

Educational Qualifications
3+ years of experience in SOC operations, cybersecurity analysis, or incident response.
Bachelors degree in Cybersecurity, Computer Science, or related field, OR equivalent hands-on experience.
Security certifications such as CompTIA CASP+, Pentest+, eCTHP, BTL2, GCIH, or similar are a plus.

Qualification

  • Technical Skills

    • In-depth understanding of security frameworks (e.g., MITRE ATT&CK) and defensive operations.

    • Proficient with SIEM, EDR, XDR, IDS/IPS, firewalls, vulnerability scanners, and email security tools.

    • Skilled in log analysis, forensic investigations, and event correlation.

    • Capable of analyzing threats across endpoints, networks, and cloud environments.

  • Soft Skills

    • Strong analytical and problem-solving abilities in complex security scenarios.

    • Excellent verbal and written communication for effective reporting and documentation.

    • Resilient under pressure; adaptable to fast-changing cybersecurity threats and priorities.


Educational Qualifications

  • 3+ years of experience in SOC operations, incident response, or cybersecurity analysis.

  • Bachelor’s degree in Cybersecurity, Computer Science, or a related field — or equivalent practical experience.

  • Preferred certifications:

    • CompTIA CASP+,

    • Pentest+,

    • eCTHP,

    • BTL2,

    • GCIH,

    • or similar credentials.

 Key job details

Primary Location
Colombo, Western Province, Sri Lanka
Job Type
Experienced
Primary Skills
XDR, EDR, Firewalls, Security Event Analysis, Log Analysis, Advanced Threat Management, Security Incident Reponse, IPS, IDS, MITRE ATT & CK, Security L1 Support, SIEM
Years of Experience
7
Travel
No
Job Posting
10/09/2025

Join Virtusa

 

Please enter a valid email address to begin your application.

Thank you for verifying your email. Please proceed with the steps below to apply.

We only accept the following file extensions: .pdf, .docx or .doc
Maximum file size: 1 MB
File name must not include special characters or spaces (e.g. “name_resume.pdf”)

We only accept the following file extensions:

Thank you. You already have an active account with Virtusa's hiring system. Please login to our portal to proceed with your application or apply for more opportunities.

LoginClick to Login

About Virtusa

Teamwork, quality of life, professional and personal development: values that Virtusa is proud to embody. When you join us, you join a team of 27,000 people globally that cares about your growth — one that seeks to provide you with exciting projects, opportunities and work with state of the art technologies throughout your career with us.

Great minds, great potential: it all comes together at Virtusa. We value collaboration and the team environment of our company, and seek to provide great minds with a dynamic place to nurture new ideas and foster excellence.

Virtusa is an Equal Opportunity Employer. All applicants will receive fair and impartial treatment without regard to race, color, religion, sex, national origin, ancestry, age, legally protected physical or mental disability, protected veteran status, status in the U.S. uniformed services, sexual orientation, gender identity or expression, marital status, genetic information or on any other basis which is protected under applicable federal, state or local law.

Applicants may be required to attend interviews in person or by video conference. In addition, candidates may be required to present their current state or government-issued ID during each interview. All candidates must be authorized to work in the USA.

Learn more

Awards and recognition

Find us on Glassdoor.

Have any questions?

What is the best way to find and apply for positions at Virtusa?

To join our bright team of professionals, you can apply directly to our website under the Careers tab and search all open jobs. https://www.virtusa.com/careers

Can I apply for more than one position at the same time?

Yes, you can. Virtusa gives you the flexibility to apply for multiple open positions that excite you about your future and align to your experience and career goals.

Can I apply for a position across multiple geographical locations?

Yes, you can. Virtusa is a global Company, and we serve our clients through our global delivery model.

What happens after I’ve submitted my resume?

Our dedicated recruitment team will review your online application and match it to all our open jobs. We update our open jobs on a daily basis and encourage you to check back often.

How will I be evaluated for a career opportunity with Virtusa?

Our team of recruiters will review your application, relevant job experience, and skills to appropriately align it to our open jobs. From there, the recruitment team will contact the qualified candidate to start the interview process.

Career insights

Want to explore the ways you can engineer your career in technology? Our thought leaders share key career insights for candidates from entry-level job seekers to senior technologists.