Security Engineering
• Participate in vendor identification and implement Cybersecurity tools for the team.
• Manage & maintain security tools & systems used for incident response.
• Create & maintain playbooks for responding to different types of security incidents.
Security Monitoring
• Respond to escalations from the SOC on security alerts, eliminate false positives, triage significant security events based on impact and nature of the security incident, and escalate according to the established procedures.
• Continuously monitor and analyse security events & newly reported threats to proactively identify any opportunities for process enhancement.
• Review automated daily security reports of key security controls, identify anomalies and, escalate critical security events to the appropriate stakeholders and follow-up as required.
• Participate in internal & external security audits.
Security Incident Response
• Conduct thorough investigative actions based on security events and remediate as dictated by standard operating procedures.
• Participate in all the phases of security incident response process, including detection, containment, eradication, root cause analysis and post-incident reporting.
• Collaborate with cross-functional teams as well as external vendors/customers/partners for incident response as required.
• Record detailed Security Incident Response activities in the Case Management System.
To ensure you’re set up for success, you will bring the following skillset & experience:• Bachelor’s Degree or equivalent in IT or Computer Science.
• Security Trainings/Certifications (e.g. SANS, CDAC-DITISS).
• 3+ years of relevant SOC IR experience.
• Should be ready to work in 24x7 rotating shifts.
• Strong analytical and reasoning abilities.
• Motivation to identify and solve problems.
• Hands-on experience with SIEM & other cybersecurity tools like AV, EDR, Firewall, SOAR.
• System & Network Log Analysis.
• Good verbal and written communication skills.
• Familiarity with various Cloud & OS environments.
• Scripting, malware analysis, vulnerability & threat analysis.