| Job Description: |
Req ID- 10365795
Job Title: Analyst
Work Location: BANGALORE, KA /HYDERABAD, TG
Skill Required: Client - Security Operations Center (SOC)
Experience : 4-6 years
Job Description: SOC L2 JDResponsibilitiesThe Security Operations Center is the central nervous system for enterprise information security responsible for monitoring, detecting, categorizing, analyzing, and initiating response to security incidents.As a Tier 2 SOC Analyst you will be an expert at identifying and responding to cyber threats against the Organization. You will be a member of the detection and response team identifying and responding to cyber threats against the Organization. Under the direction of management or a senior analyst you will analyze and respond to well-defined threats and assist with more complex threats.THE PERSONThe ideal candidate will possess strong multi-tasking skills and enthusiasm for details and should think one step ahead of cybercriminals. They should have an insatiable curiosity and deep understanding of How Things Work from which to understand how things might be abused. They should be well prepared to thrive in a fast-paced environment, possessing strong interpersonal and communication skills.KEY RESPONSIBILITIES- Incident handler with experience handling sensitiveneed-to-know incidents. You will understand CSIRT best practices and the Organization incident response model, and will adapt both as appropriate to resolve specific incidents. You will coordinate with external teams to get the support needed for incident closure.- Understand, use, monitor, and optimize existing SIEM rules and SOAR processes. You will continually look for ways to improve detection accuracy and reduce false positive alerts, and for ways to accelerate or automate response processes.- Propose and develop new use cases and playbooksSOPs. You will propose and develop automation for recurring incidents and incident tasks, and will identify and onboard new datasources to support new threat detection and response use cases.- Assist with operation, configuration, monitoring and tuning of an enterprise SIEM platform, including log collection specifications and infrastructure, and data source onboarding.- Collaborate with technical and business experts from partner organizations including IT, Engineering, Finance, AuditCompliance, HRLegal, Corporate Investigations.- Escalation point for a global 24x7x365 SOC environment.IDEAL CANDIDATE WILL HAVE- 3 years experience as a SOC Analyst, or a Network Analyst with security scope, preferably in a large enterprise environment- Experience in working with a geographically diverse team in multiple time zones around the globe- Deep understanding of the ATTCK matrix, with demonstrated experience building use cases and SOPs around the TTPs most relevant to your business.- Proficient technical writing skills (documenting processes and procedures)- Ability to solve problems and work through ambiguity and uncertainty- Proficiency in common scripting languages such as PowerShell, Bash, Python, etc.- Proficiency with one or more SIEM query language- Workin
Essential Skills: SOC L2 ResponsibilitiesThe Security Operations Center is the central nervous system for enterprise information security responsible for monitoring, detecting, categorizing, analyzing, and initiating response to security incidents.As a Tier 2 SOC Analyst you will be an expert at identifying and responding to cyber threats against the Organization. You will be a member of the detection and response team identifying and responding to cyber threats against the Organization. Under the direction of management or a senior analyst you will analyze and respond to well-defined threats and assist with more complex threats.THE PERSONThe ideal candidate will possess strong multi-tasking skills and enthusiasm for details and should think one step ahead of cybercriminals. They should have an insatiable curiosity and deep understanding of How Things Work from which to understand how things might be abused. They should be well prepared to thrive in a fast-paced environment, possessing strong interpersonal and communication skills.KEY RESPONSIBILITIES- Incident handler with experience handling sensitiveneed-to-know incidents. You will understand CSIRT best practices and the Organization incident response model, and will adapt both as appropriate to resolve specific incidents. You will coordinate with external teams to get the support needed for incident closure.- Understand, use, monitor, and optimize existing SIEM rules and SOAR processes. You will continually look for ways to improve detection accuracy and reduce false positive alerts, and for ways to accelerate or automate response processes.- Propose and develop new use cases and playbooksSOPs. You will propose and develop automation for recurring incidents and incident tasks, and will identify and onboard new datasources to support new threat detection and response use cases.- Assist with operation, configuration, monitoring and tuning of an enterprise SIEM platform, including log collection specifications and infrastructure, and data source onboarding.- Collaborate with technical and business experts from partner organizations including IT, Engineering, Finance, AuditCompliance, HRLegal, Corporate Investigations.- Escalation point for a global 24x7x365 SOC environment.IDEAL CANDIDATE WILL HAVE- 3 years experience as a SOC Analyst, or a Network Analyst with security scope, preferably in a large enterprise environment- Experience in working with a geographically diverse team in multiple time zones around the globe- Deep understanding of the ATTCK matrix, with demonstrated experience building use cases and SOPs around the TTPs most relevant to your business.- Proficient technical writing skills (documenting processes and procedures)- Ability to solve problems and work through ambiguity and uncertainty- Proficiency in common scripting languages such as PowerShell, Bash, Python, etc.- Proficiency with one or more SIEM query language- Workin |
| Comments for Suppliers: |
|
|