30 Jul
|
agility human resource management services
|
Maharashtra
30 Jul
agility human resource management services
Maharashtra
Role & responsibilities
Investigate and respond to alerts escalated by SOC team, conducting in-depth analysis before closure.
• Utilize SentinelOne EDR, Splunk, QRadar, and ArcSight for advanced threat validation and investigation.
• Apply MITRE ATT&CK; framework to classify threats and recognize adversary techniques.
- Collaborate with cross-functional teams to enhance detection rules and response procedures.
- Develop detailed RCA reports and contribute to the creation of incident response playbooks. • Monitor emerging threats and recommend proactive defensive measures. • Work with DLP solutions like Forcepoint DLP to detect and prevent data exfiltration. • Analyzed alert patterns during incident investigations and collaborated with SOC and engineering teams to suggest fine-tuning of detection logic and rule parameters.
Hands-on Experience with SIEM tools FortiSIEM and SECEON including creating and fine tuning rules.
Hands-on Experience with XDR tools SOPHOS Central and s1 with Onboarding End Devices Incident Response:
Solid expertise in triage, containment, remediation, and post-incident documentation.
Threat Hunting: Skilled in hypothesis-driven threat hunting to detect hidden adversaries using behavioral analysis and IOCs
Preferred candidate profile
Proficient in security monitoring, log analysis, incident detection and response,and proactive threat hunting.
Level 2 (L2):
Advanced Incident Response:
Investigate and resolve escalated incidents from L1.
Perform root cause analysis and recommend preventive measures.
Vulnerability Management:
Analyse vulnerability reports, prioritise remediation, and coordinate with infra teams.
Security System Administration:
Manage and fine-tune configurations for:
CrowdStrike (EDR)
ColorTokens (Micro Segmentation)
AppTrana (WAF)
Forcepoint (DLP, Email Security)
Trend Micro/Trellix (Full Disk Encryption)
Splunk (SIEM)
Netskope (Web Proxy)
IBM Guardium (DAM)
Azure Information Protection & Klassify (Data Classification)
Intune (MDM)
Cymmetri (IAM)
SecHard (Security Hardening)
FireCompass (Attack Surface Monitoring)
Policy Enforcement & Compliance:
Ensure adherence to security policies and regulatory requirements.
Threat Hunting & Red Team Coordination:
Collaborate with FireCompass for attack surface monitoring and red teaming exercises.
Reporting & Metrics:
Generate weekly/monthly security posture reports for management.
For L2:
35 years of experience in Security Operations.
Hands-on experience with multiple security technologies listed above.
Knowledge of vulnerability management frameworks and incident response processes.
Ability to work under pressure and manage critical incidents.
Certifications (Preferred):
CompTIA Security+, CEH, or equivalent for L1.
CISSP, CISM, or equivalent for L2.
email :
[email protected]
(phone hidden)
📌 SOC Engineer ( Can join in 15 days) (Maharashtra)
🏢 agility human resource management services
📍 Maharashtra