Employment Type: Full time | Onsite Role Overview The set of skills and responsibilities required by us, focuses on defensive security, real-time monitoring, incident response, and threat detection. Key Responsibilities
Incident Management: Manage and respond to security incidents; conduct root cause analysis and post-incident reviews.
Monitoring & Analysis: Analyze logs and alerts from various sources (Firewall, Windows, Unix, WAF, AV, EDR/MDR) using SIEM technologies.
SIEM Engineering: Author and fine-tune SIEM rules, reports, and parsers.
Threat Hunting: Leverage internal and external threat intelligence to investigate and hunt threats.
Endpoint Security: Work closely with Endpoint Detection and Response (EDR) solutions.
Automation:
Identify automation and orchestration opportunities to streamline SOC operations.
Technical
Competencies
In-depth understanding of SIEM and endpoint detection & response (EDR/MDR) tools.
Experience in threat intelligence analysis and incident lifecycle management.
Proficiency in Network Security and Incident Management.
Technologies & Tools
SIEM: ArcSight, Splunk, QRadar, Elastic (Exposure to Elastic SIEM is an added advantage).
EDR/MDR: CrowdStrike, Carbon Black, MS Defender.
Required
Qualifications
Education: Bachelor of Science (BSc).
Personal Traits: Quick learner with a proactive approach to problem-solving.