Monitor and investigate security alerts across SIEM, endpoint, identity, email, network, and cloud platforms. Conduct incident response from detection through recovery, including containment, evidence preservation, scoping, and timeline reconstruction. Tune detection logic, reduce false positives, maintain runbooks, identify automation opportunities, and report coverage gaps. Collaborate with security, IT, engineering, and application teams, document investigations, support P1 incidents, and participate in response exercises. The role requires schedule flexibility for evenings, weekends, and holidays.
At Rocket India, we're not just building technology - we're building trust. Every transaction, every data point, every customer interaction is protected by the people who refuse to let threats go unanswered. Our Security Operations Center is the nerve center of that mission, and we're looking for a vigilant, curious, and driven SOC Analyst to stand as our first line of defense. If you thrive in fast-paced environments, love piecing together the puzzle of suspicious activity, and want your work to directly safeguard the dream of homeownership for millions - this is your moment.
About the Role
Alert Triage and Investigation
Incident Response
Detection Quality and Continuous Improvement
About You
Minimum Qualifications:
Preferred Qualifications:
What You Will Get
At Rocket India, you'll join a security team that doesn't just react - it evolves. You'll have access to best-in-class security tooling, continuous learning opportunities, and a collaborative culture where your insights directly shape how we protect our business and our clients. We offer competitive compensation, comprehensive health benefits, flexible work arrangements, and investment in your professional development through certifications, training, and mentorship. Your vigilance keeps millions of homeowners safe, and we make sure you're recognized and rewarded for it.
About Us
Rocket India, registered as NSM Services Private Limited and formerly Mr. Cooper, is a wholly owned subsidiary of Rocket Mortgage, LLC, headquartered in Detroit, Michigan. As a core part of Rocket's global ecosystem, Rocket India helps shape the future of home financing through technology, innovation, operations, product, and customer-focused solutions. Our teams build scalable platforms and digital experiences that simplify mortgage origination and servicing while supporting Rocket's mission to "Help Everyone Home."
We are committed to providing a fair and inclusive workplace for all team members and applicants. All qualified applicants will receive consideration for employment without regard to sex, religion, caste, disability, or gender identity, consistent with applicable Indian law, including the Constitution of India, the Code on Wages, 2019, the Rights of Persons with Disabilities Act, 2016, and the Transgender Persons (Protection of Rights) Act, 2019. We welcome applications from persons with disabilities and from all sections of society.
About the Role
Alert Triage and Investigation
- Monitor and triage alerts across SIEM, endpoint detection and response, email security, identity, and cloud security platforms, prioritizing by risk and potential business impact
- Investigate suspicious activity to a conclusion, pivoting across multiple telemetry sources to confirm or rule out malicious behavior
- Classify observed activity against a recognized framework such as MITRE ATT&CK to support consistent categorization and trend analysis
- Analyze reported phishing, endpoint detections, identity anomalies, and cloud misconfiguration alerts, recording findings and reasoning in the case record
- Review indicators using threat intelligence and malware analysis tooling to establish reputation and observed behavior
- Escalate confirmed or suspected incidents promptly, with a clear summary of what is known, what remains unverified, and recommended next steps
Incident Response
- Apply the incident response lifecycle - detection and analysis, containment, eradication, recovery, and post-incident review - to owned incidents
- Determine blast radius and reconstruct attack timelines by correlating endpoint, identity, network, and log telemetry
- Execute containment actions such as host isolation, account disablement, and indicator blocking, escalating when scope or business impact exceeds the severity threshold for independent action
- Collect and preserve evidence, maintaining sound chain of custody
- Support the incident response lead on P1 incidents by providing scoping, evidence, and timeline reconstruction
- Maintain the incident record throughout an event and contribute to post-incident reviews, after-action reports, and lessons learned
- Partner with ThreatOps, SecOps Engineering, IT, and application teams to validate findings and coordinate remediation
- Participate in tabletop exercises and response drills to build and maintain readiness
Detection Quality and Continuous Improvement
- Tune detection logic to reduce false positives, documenting the rationale and the risk accepted for every suppression or threshold change
- Track recurring alert patterns and identify candidates for automation, submitting them to SecOps Engineering for evaluation and build
- Maintain and improve triage runbooks so investigative steps are repeatable across the team
- Report detection coverage gaps observed during casework so they can be addressed
About You
Minimum Qualifications:
- 1 year in an information security analyst or SOC analyst role
- 3 years of experience in a technology role
- Bachelor's degree in information assurance, computer science, or a related field, or equivalent experience
- Hands-on experience with a SIEM, including log search, correlation, and alert triage across large structured and unstructured data sets
- Working knowledge of endpoint detection and response tooling and the investigative workflow it supports
- Proficiency in operating systems (Windows, macOS, Linux/Unix, mobile) and core network theory, including common protocols and basic traffic analysis
- Ability to read and interpret scripts, and to write basic scripts or queries in support of an investigation
- Familiarity with common attacker techniques and a recognized classification framework such as MITRE ATT&CK
- Working understanding of the incident response lifecycle and the ability to apply it to live incidents
- Clear written communication - able to document an investigation so a colleague can pick it up without a verbal handoff
- Schedule flexibility - must be available to work outside standard business hours, including evenings, weekends, and holidays, as incident severity and volume demand
Preferred Qualifications:
- 4 years in an information security analyst or SOC analyst role
- 6 years of experience in a technology role
- Experience owning incidents through containment and recovery in an enterprise environment
- Demonstrated experience tuning detection logic and measurably reducing false positive volume
- Exposure to security automation or SOAR platforms, with an eye for identifying automation opportunities
- Certifications such as Security+, ISC2 credentials (SSCP or CISSP Associate), or GSEC; incident response credentials such as GCIH or GCFA are especially valued
- Experience with cloud security monitoring (AWS, Azure, GCP) and detection of identity-based attacks
- Experience in the mortgage, financial services, or another regulated industry
What You Will Get
At Rocket India, you'll join a security team that doesn't just react - it evolves. You'll have access to best-in-class security tooling, continuous learning opportunities, and a collaborative culture where your insights directly shape how we protect our business and our clients. We offer competitive compensation, comprehensive health benefits, flexible work arrangements, and investment in your professional development through certifications, training, and mentorship. Your vigilance keeps millions of homeowners safe, and we make sure you're recognized and rewarded for it.
About Us
Rocket India, registered as NSM Services Private Limited and formerly Mr. Cooper, is a wholly owned subsidiary of Rocket Mortgage, LLC, headquartered in Detroit, Michigan. As a core part of Rocket's global ecosystem, Rocket India helps shape the future of home financing through technology, innovation, operations, product, and customer-focused solutions. Our teams build scalable platforms and digital experiences that simplify mortgage origination and servicing while supporting Rocket's mission to "Help Everyone Home."
We are committed to providing a fair and inclusive workplace for all team members and applicants. All qualified applicants will receive consideration for employment without regard to sex, religion, caste, disability, or gender identity, consistent with applicable Indian law, including the Constitution of India, the Code on Wages, 2019, the Rights of Persons with Disabilities Act, 2016, and the Transgender Persons (Protection of Rights) Act, 2019. We welcome applications from persons with disabilities and from all sections of society.
Similar Jobs at Rocket
Fintech • Real Estate • Sales • Financial Services
Lead complex C#/.NET feature and system development, make architectural decisions, manage technical debt, and establish engineering standards. Mentor engineers, drive code quality, security, observability, testing, and CI/CD practices. Lead critical incident response and root-cause analysis while improving system resilience. Collaborate with product and architecture teams on technical tradeoffs, distributed systems, cloud architecture, migrations, and scalable production solutions.
Top Skills:
.Net.Net FrameworkAmazon SqsApplication InsightsAsp.Net CoreAuthhubAzureAzure DevopsAzure Service BusC#DockerDynatraceEntity Framework CoreKubernetesOauth
Fintech • Real Estate • Sales • Financial Services
Develop, test, and deliver production features using C#/.NET. Own features end-to-end, collaborate with product and design, participate in code reviews, maintain automated test coverage, troubleshoot production issues, and improve reliability and performance. Contribute to CI/CD, architectural standards, and engineering tooling while informally mentoring junior engineers. Participate in on-call rotations and collaborate cross-functionally to deliver scalable microservices and REST-based solutions.
Top Skills:
.Net 8.Net CoreAsp.Net CoreAzure DevopsAzure Service BusC#/.NetDapperDistributed TracingDockerEntity Framework CoreGitKafkaKubernetesLoggingMicroservicesAzureMonitoringMvcNunitRabbitMQRest ApisWeb ApiXunit
Fintech • Real Estate • Sales • Financial Services
Internship supporting investor services activities related to the Mr. Cooper integration. The posting provides no further details about specific responsibilities, qualifications, technologies, compensation, travel, or work arrangements.
What you need to know about the Chennai Tech Scene
To locals, it's no secret that South India is leading the charge in big data infrastructure. While the environmental impact of data centers has long been a concern, emerging hubs like Chennai are favored by companies seeking ready access to renewable energy resources, which provide more sustainable and cost-effective solutions. As a result, Chennai, along with neighboring Bengaluru and Hyderabad, is poised for significant growth, with a projected 65 percent increase in data center capacity over the next decade.

