- Strong hands-on experience with Azure Sentinel and Microsoft Defender for O365.
- Understanding of security events and situations in Azure Sentinel and MS defender.
- Understanding of sentinel services, SOAR and implementing.
- Identifying potential threats and performing enhancements to existing cyber security measures as per specifications or policy guidelines.
- Hands on experience working in 24*7 SOC operations, handling security alerts, Incident triage and investigation, providing SOC Tier 2 support.
- Good understanding of Cyber security, EDR, Phishing analysis etc.
- Responsibilities include cyber threat analysis support and recommending appropriate remediation and mitigation.
- Oversees and coordinates 24*7 security operations within an organization.
- Deep expertise in delivering security operations from a MSSP.
- Manage personnel/staffing, budget, shift scheduling and technology strategy to meet SLAs.
- Serves as organizational point person for business-critical incidents.
- Strong understanding of the SOC KPIs, establish SOC performance goals and priorities.
- Manages security teams, monitors threat, implements security policies, and collaborates with other departments to ensure a comprehensive security posture.
- Suggests detective and preventive controls to the organizations in helping them become cyber aware, has knowledge of the latest cybersecurity trends.
- Understanding of the cybersecurity framework such as NIST, MITRE ATT&CK;(attack lifecycle management).