SOC Analyst (L1) — Konfirmity | Bengaluru, Electronics City
Konfirmity
Role tags
Tech stack mentioned
Role overview
Formatting this description...
Cloud engineering and DevOps are being eaten by AI faster than most people in those roles want to admit. A lot of what used to be a career — writing the Terraform, wiring the pipeline, tuning the cluster — is now a prompt away. Security isn't going the same way. The tooling is getting better, and the agents help, but the judgment call at the end of an alert still belongs to a person. Someone has to decide whether this is real, and what it means, and what to do at 0300. If you're a DevOps or cloud engineer, or you were heading that way and have started to wonder about it — this is the field to move into. And this is the role that moves you. What we'll make you Not an alert-closer. A security engineer who understands cloud, applications, environments, and both sides of the fight — offensive and defensive. That's not a promise we make loosely. It's structural: we don't have a wall between the SOC and the pen-test team, so you'll spend your time on both. What makes our SOC different We don't just watch data. We use it to attack our own clients. Every signal we collect feeds back into offensive testing — we take what the telemetry tells us and build fake attacks against the client's real environment to prove whether the defence actually holds. Detection and offence run as one loop, not two teams. We look across every layer of an organisation: device, network, wifi, cloud, application, code, and the attack surface itself. Signals from all of them get correlated, and then used against the client, on purpose, so the gaps surface before someone else finds them. It's AI-driven — our platform runs a multi-agent detection and triage layer, so your job isn't clearing false positives by hand. It's the judgment calls the agents escalate to you. What you'll do Monitor and triage alerts across AWS, Azure, Entra ID, GCP, Cloudflare Zero Trust and Intune etc. Investigate detections mapped to MITRE ATT&CK and decide what's real Handle first-line incident response and escalate with evidence and reasoning Feed detection findings into our offensive testing cycle Work alongside our pen-testing team — you'll see both sides of the same problem What we're looking for 2–4 years in cloud or security operations Hands-on with at least two of: AWS, Azure/Entra ID, GCP Familiarity with AI tools and comfort working alongside agent-based systems Sound investigative instinct — we care more about how you think through an alert than which tools you've memorised Willing to work a 24×7 rotation You do not need a security background. If you've got the cloud and the curiosity, we'll build the rest. Your first two weeks You don't go near production on day one. We run a two-week training and trial period covering security fundamentals, cloud, DevOps, and our incident playbooks — worked through against real incidents we've handled, not hypotheticals. At the end of it you're assessed on what you've actually absorbed, and you move to live shifts once you clear that. It works both ways. Two weeks is long enough for you to find out whether this work suits you before you've committed to a night rotation. The shift pattern — stated plainly We run 24×7×365. Three shifts: 0600–1400, 1400–2200, 2200–0600. Five days a week, with a 30-minute handover overlap at each boundary. You will work nights. The rotation puts you on a full week of nights roughly once a month — about 13 night weeks a year. Nights carry an allowance of 10% per week on top of base. There's an optional 6-day week at 15% per month extra, if you want it. It's opt-in, never assigned. Leave: 10 public holidays and 18 earned leave days a year. If night work doesn't suit your life right now, that's a reasonable thing to know about yourself — and better to know before you apply than three months in. Where Bengaluru, Electronics City. On-site. Why this role is worth your time You'll be one of a small team, not a name in a rota of forty. Everything is in-house — we don't subcontract our pen testing, so the offensive work you feed into is done by people sitting near you. And you'll see how security work actually connects to ISO 27001, SOC 2 and MAS TRM in practice, rather than as a checkbox someone else ticks.