Monitor and triage security alerts across SIEM, endpoint, email, identity, and cloud platforms. Investigate suspicious activity, analyze phishing and endpoint events, map threats to MITRE ATT&CK, and manage incidents through containment and recovery. Preserve evidence, reconstruct attack timelines, tune detection logic, maintain runbooks, identify automation opportunities, and collaborate on remediation. The role requires flexible availability for evenings, weekends, holidays, and high-severity incidents.
At Rocket India, security isn't just a function - it's a promise. Every alert we investigate, every threat we neutralize, and every detection we refine protects the financial futures of millions of families working toward homeownership. Our Security Operations Center operates at the intersection of technology and trust, and we need a sharp, relentless SOC Analyst who sees patterns where others see noise, who treats every signal with the seriousness it deserves, and who's ready to be the shield that never sleeps. If you want your career in cybersecurity to have real-world impact at scale, welcome to the front line.
About the Role
Alert Triage and Investigation
Incident Response
Detection Quality and Continuous Improvement
About You
Minimum Qualifications:
Preferred Qualifications:
What You Will Get
At Rocket India, defending the organization means you're also investing in yourself. You'll operate with industry-leading security tooling, gain exposure to sophisticated threat landscapes, and grow within a team that values curiosity and continuous learning. We provide competitive compensation, comprehensive health coverage, certification sponsorship, and a culture that celebrates the people who keep us safe. Whether it's advancing your credentials, contributing to automation that makes the team faster, or stepping up during critical incidents - every contribution here accelerates your career and protects what matters most.
About Us
Rocket India, registered as NSM Services Private Limited and formerly Mr. Cooper, is a wholly owned subsidiary of Rocket Mortgage, LLC, headquartered in Detroit, Michigan. As a core part of Rocket's global ecosystem, Rocket India helps shape the future of home financing through technology, innovation, operations, product, and customer-focused solutions. Our teams build scalable platforms and digital experiences that simplify mortgage origination and servicing while supporting Rocket's mission to "Help Everyone Home."
We are committed to providing a fair and inclusive workplace for all team members and applicants. All qualified applicants will receive consideration for employment without regard to sex, religion, caste, disability, or gender identity, consistent with applicable Indian law, including the Constitution of India, the Code on Wages, 2019, the Rights of Persons with Disabilities Act, 2016, and the Transgender Persons (Protection of Rights) Act, 2019. We welcome applications from persons with disabilities and from all sections of society.
About the Role
Alert Triage and Investigation
- Serve as the first line of defense by monitoring and triaging alerts across SIEM, endpoint detection and response, email security, identity, and cloud security platforms - always prioritizing by risk and business impact
- Investigate suspicious activity to a definitive conclusion, pivoting across multiple telemetry sources to confirm or rule out malicious behavior
- Map observed activity to a recognized framework such as MITRE ATT&CK, enabling consistent categorization and meaningful trend analysis
- Analyze reported phishing attempts, endpoint detections, identity anomalies, and cloud misconfiguration alerts - meticulously recording findings and reasoning in the case record
- Leverage threat intelligence and malware analysis tooling to assess indicator reputation and observed behavior
- Escalate confirmed or suspected incidents with precision - delivering a clear summary of what is known, what remains unverified, and recommended next steps
Incident Response
- Own incidents below P1 through the full incident response lifecycle - detection and analysis, containment, eradication, recovery, and post-incident review
- Determine blast radius and reconstruct attack timelines by correlating endpoint, identity, network, and log telemetry
- Execute decisive containment actions including host isolation, account disablement, and indicator blocking - escalating when scope or business impact demands it
- Collect and preserve digital evidence with sound chain-of-custody practices
- Support the incident response lead on P1 events by providing scoping intelligence, evidence, and timeline reconstruction
- Maintain thorough incident records and contribute meaningfully to post-incident reviews, after-action reports, and lessons learned
- Collaborate with ThreatOps, SecOps Engineering, IT, and application teams to validate findings and drive coordinated remediation
- Participate in tabletop exercises and response drills to sharpen readiness across the team
Detection Quality and Continuous Improvement
- Tune detection logic to reduce false positives, documenting the rationale and accepted risk for every suppression or threshold change
- Identify recurring alert patterns and surface automation candidates to SecOps Engineering for evaluation and build
- Maintain and enhance triage runbooks to ensure investigative steps are repeatable and consistent across the team
- Report detection coverage gaps uncovered during casework to strengthen the organization's security posture
About You
Minimum Qualifications:
- 1 year in an information security analyst or SOC analyst role
- 3 years of experience in a technology role
- Bachelor's degree in information assurance, computer science, or a related field, or equivalent experience
- Hands-on experience with a SIEM, including log search, correlation, and alert triage across large structured and unstructured data sets
- Working knowledge of endpoint detection and response tooling and the investigative workflow it supports
- Proficiency in operating systems (Windows, macOS, Linux/Unix, mobile) and core network theory, including common protocols and basic traffic analysis
- Ability to read and interpret scripts, and to write basic scripts or queries in support of an investigation
- Familiarity with common attacker techniques and a recognized classification framework such as MITRE ATT&CK
- Working understanding of the incident response lifecycle and the ability to apply it to live incidents
- Clear written communication - able to document an investigation so a colleague can pick it up without a verbal handoff
- Schedule flexibility - must be available to work outside standard business hours, including evenings, weekends, and holidays, as incident severity and volume demand
Preferred Qualifications:
- 3 years in an information security analyst or SOC analyst role
- 5 years of experience in a technology role
- Experience owning incidents through containment and recovery in an enterprise environment
- Demonstrated experience tuning detection logic and measurably reducing false positive volume
- Exposure to security automation or SOAR platforms, with a keen eye for identifying automation opportunities
- Certifications such as Security+, ISC2 credentials (SSCP or CISSP Associate), or GSEC; incident response credentials such as GCIH or GCFA are especially valued
- Experience with cloud security monitoring (AWS, Azure, GCP) and detection of identity-based attacks
- Experience in the mortgage, financial services, or another regulated industry
What You Will Get
At Rocket India, defending the organization means you're also investing in yourself. You'll operate with industry-leading security tooling, gain exposure to sophisticated threat landscapes, and grow within a team that values curiosity and continuous learning. We provide competitive compensation, comprehensive health coverage, certification sponsorship, and a culture that celebrates the people who keep us safe. Whether it's advancing your credentials, contributing to automation that makes the team faster, or stepping up during critical incidents - every contribution here accelerates your career and protects what matters most.
About Us
Rocket India, registered as NSM Services Private Limited and formerly Mr. Cooper, is a wholly owned subsidiary of Rocket Mortgage, LLC, headquartered in Detroit, Michigan. As a core part of Rocket's global ecosystem, Rocket India helps shape the future of home financing through technology, innovation, operations, product, and customer-focused solutions. Our teams build scalable platforms and digital experiences that simplify mortgage origination and servicing while supporting Rocket's mission to "Help Everyone Home."
We are committed to providing a fair and inclusive workplace for all team members and applicants. All qualified applicants will receive consideration for employment without regard to sex, religion, caste, disability, or gender identity, consistent with applicable Indian law, including the Constitution of India, the Code on Wages, 2019, the Rights of Persons with Disabilities Act, 2016, and the Transgender Persons (Protection of Rights) Act, 2019. We welcome applications from persons with disabilities and from all sections of society.
Similar Jobs at Rocket
Fintech • Real Estate • Sales • Financial Services
Lead complex C#/.NET feature and system development, make architectural decisions, manage technical debt, and establish engineering standards. Mentor engineers, drive code quality, security, observability, testing, and CI/CD practices. Lead critical incident response and root-cause analysis while improving system resilience. Collaborate with product and architecture teams on technical tradeoffs, distributed systems, cloud architecture, migrations, and scalable production solutions.
Top Skills:
.Net.Net FrameworkAmazon SqsApplication InsightsAsp.Net CoreAuthhubAzureAzure DevopsAzure Service BusC#DockerDynatraceEntity Framework CoreKubernetesOauth
Fintech • Real Estate • Sales • Financial Services
Develop, test, and deliver production features using C#/.NET. Own features end-to-end, collaborate with product and design, participate in code reviews, maintain automated test coverage, troubleshoot production issues, and improve reliability and performance. Contribute to CI/CD, architectural standards, and engineering tooling while informally mentoring junior engineers. Participate in on-call rotations and collaborate cross-functionally to deliver scalable microservices and REST-based solutions.
Top Skills:
.Net 8.Net CoreAsp.Net CoreAzure DevopsAzure Service BusC#/.NetDapperDistributed TracingDockerEntity Framework CoreGitKafkaKubernetesLoggingMicroservicesAzureMonitoringMvcNunitRabbitMQRest ApisWeb ApiXunit
Fintech • Real Estate • Sales • Financial Services
Internship supporting investor services activities related to the Mr. Cooper integration. The posting provides no further details about specific responsibilities, qualifications, technologies, compensation, travel, or work arrangements.
What you need to know about the Chennai Tech Scene
To locals, it's no secret that South India is leading the charge in big data infrastructure. While the environmental impact of data centers has long been a concern, emerging hubs like Chennai are favored by companies seeking ready access to renewable energy resources, which provide more sustainable and cost-effective solutions. As a result, Chennai, along with neighboring Bengaluru and Hyderabad, is poised for significant growth, with a projected 65 percent increase in data center capacity over the next decade.

