Role : Lead security incident response
ECMS Requirement Format |
|
Number of Openings |
4 |
|
ECMS ID in sourcing stage |
|
|
Assignment Duration |
6 months+ |
|
Total Yrs. of Experience |
5+ |
|
Relevant Yrs. of experience |
5+ |
|
Detailed JD (Roles and Responsibilities) |
- Lead security incident response in a cross-functional environment and drive incident resolution.
- Lead and develop Incident Response initiatives that improve customer capabilities to effectively respond and remediate security incidents.
- Perform digital forensic investigations and analysis of a wide variety of assets including endpoints.
- Perform log analysis from a variety of sources to identify potential threats.
- Build automation for response and remediation of malicious activity.
- Write complex search queries in the EDR as well as SIEM tools for hunting the adversaries.
- Works on SOAR cases, automation, workflow & Playbooks.
- Integrating and working on Identity solutions.
- Developing SIEM use cases for new detections specifically on identity use cases
- Working experience in Microsoft On-prem and Entra ID solutions
- Good knowledge in Active Directories and Tier 0 concepts
- Very good knowledge of operating systems, processes, registries, file systems, and memory structures and experience in host and memory forensics (including live response) on Windows, macOS and Linux.
- Experience investigating and responding to both external and insider threats.
- Experience with attacker tactics, techniques, and procedures (MITRE Telecommunication&CK)
Experience analyzing network and host-based security events
|
|
| |
| |
| |
Mandatory skills |
|
|
Desired/ Secondary skills |
|
|
Domain |
SOC, Lead- Incident Response |
|
Max Vendor Rate in Per Day (Currency in relevance to work location) |
12000 INR / Day |
|
Work Location given in ECMS ID |
Pune |
|
WFO/WFH/Hybrid WFO |
WFO |
|
BG Check (Before OR After onboarding) |
|
|
Is there any working in shifts from standard Daylight (to avoid confusions post onboarding) YES/ NO |
|