Cybersecurity Admin Sec - SIEM Administrator
Job Description
Greeting From TCS!!!
\nRole: Cybersecurity Admin Sec - SIEM Administrator
\nExperience: 8 to 12
\nLocation: Chennai
\nSN
\nResponsibility of / Expectations from the Role
\n1
\nConduct proactive threat hunting activities across endpoints, networks, cloud environments, and identity platforms. - Develop and execute threat hunting hypotheses based on threat intelligence, emerging attack trends, and organizational risks.
\n- Identify Indicators of Compromise (IoCs), Indicators of Attack (IoAs), and suspicious behaviors.
\n2
\nAnalyze security events to detect stealthy, persistent, and advanced threats.
\n- Consume and operationalize cyber threat intelligence feeds.
\n3
\nMap adversary tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework.
\n- Track emerging threats, vulnerabilities, and attack campaigns.
\n- Document hunting findings, attack patterns, and remediation recommendations.
\n- Present threat hunt outcomes to security leadership and stakeholders.
\n4
\nCollaborate with SOC, Incident Response, Vulnerability Management, Red Team, and Security Engineering teams.
\nDevelop scripts and automation to improve threat hunting and investigation efficiency.
\n5
\nContinuously evaluate and improve security monitoring and detection coverage.
\nContribute to purple team exercises and detection validation activities.
\n6
\nEnhance threat detection capabilities within SIEM, EDR, NDR, and XDR platforms.
\n7
\nDevelop hunt queries using KQL, SPL, SQL, Sigma, YARA, or similar technologies.
\n8
\nSupport incident response activities for malware infections, ransomware, insider threats, credential compromise, and APT attacks.