Description
Role
Cyber Security Ops Analyst
Role Brief
This role will support threat monitoring, detection, event analysis, incident response/reporting, forensics, and threat hunting activities for our Cyber Defense Center (SOC), which is a 24/7 environment.
The SOC Analyst must be able to rapidly respond to security incidents and should have relevant experience in Cyber security incident response and have a deeper understanding with some hands-on experience on enterprise IT infra components.
Responsibilities:
- Providing incident response/investigation and remediation support for escalated security alerts/incidents (should be flexible to work in 24*7 environment).
- Leverages emerging threat intelligence (IOCs, updated rules, etc.) to identify affected systems and the scope of the attack.
- Performing comprehensive computer monitoring, identifying vulnerabilities, Target mapping and profiling.
- Develop, update and maintain log baselines for all platforms.
- Conduct Threat hunting to detect complex cyber incidents in addition to the rule-based detections.
- Provides support for complex computer/network exploitation and Defense techniques to include deterring, identifying, and investigating computer and network intrusions.
- Provides technical support for forensics services to include evidence seizure, computer forensic analysis and data recovery, in support of computer crime investigation. Researches and maintains proficiency in open and closed source computer exploitation tools, attack techniques, procedures and trends.
- Performs research into emerging threat sources and develop threat profiles. Keep updated on the latest cybersecurity threats.
- Provide recommendations on how to improve security posture from the technical perspective.
- Install/configure/build/fine-tune the SIEM tools to setup an effective information security support / operation.
- Establish KPI, review & manage security logs and provide reports based on KPI and metrics.
- Look for opportunities to automate repeated tasks.
- Participation in regular meetings with other stake holders to innovate and introduce heightened security detection rules.
- Maintain meticulous records of security monitoring and incident response activities.
Required Skills and Abilities:
- 6+ years previous working experience in a SOC or Cyber Security Role with last 2 years in an L2 or above role.
- Knowledge of various operating systems.
- Prior experience in detecting, analysing and investigating security incidents.
- Excellent experience in threat intelligence, network forensics.
- Strong, verbal, and written communication, facilitation, and interpersonal skills.
- Has a sound understanding of SIEM, PAM, IAM,DAM,CASB, EDR, other threat detection platforms and Incident Response tools.
- Has a systematic, disciplined and analytical approach to problem-solving, knowledge of current threat landscape (threat actors, APT, cyber-crime, etc.)
- Has knowledge of Data Loss Prevention monitoring
- Has knowledge of audit requirements (PCI, HIPPA, SOX, etc.)
Required Experience in administrating or monitoring detection/security tools:
SIEM
- EDR
- Endpoint Protection
- IPS/IDS
- DLP
- Cloud Security (GCP. AWS, Azure)
- Identity and Access Management
- Firewalls and Networking
- Demonstrates strong evidence of analytical ability and attention to detail. Has a broad understanding of all stages of incident response.
- Good understanding of security and incident response activities
- Core understanding of possible attacks activities such as network probing/scanning, DDOS, etc.
- Good understanding of vulnerability assessment tools
- Ability to complete tasks and deliver on time, and good interaction with other teams
- Self-Motivated, curious, and knowledgeable pertaining to new and current information security trends and news.
Minimum qualifications - Graduation ( BE/B.Tech/ MCA)
- Certified in any Leading SIEM Tools like Arcsight, Logrhythm, Qradar, Splunk.
Preferred qualifications
Security Certifications Preferred (Including but not limited to the following certifications):
Certified Incident Handler (GCIH),GCIA, GDAT,GMON, OSCP, CHFI,