Continuous monitoring the SIEM dashboard for alerts and incidents
Monitoring of console of Cyber Security tools like Anti-APT, WAF, DLP etc to identify the security events and health status on need basis.
Perform first level event analysis for identified alerts before qualifying the incidents.
Categorize/Triage the Security Incidents as per incident management procedure / playbook and assign to the respective owner.
Analyse the security events / alerts for any false positive.
Report / escalate the critical Cyber Security Incidents or in case of SLA breach.
Follow the play books and SOC procedures for incident management.
Log security Incidents in ticketing tool, assign it to the respective team and track for closer. Prepare the report and trackers for cyber security incidents.
Candidate must work in 24x7 in shift duties which may include holidays, and weekends.
Participate and contribute to all SOC related activities like cyber drills or exercises.
Solid understand on OSI layers, LAN/WAN technologies and TCP/IP protocols
Trained on SOC operations i.e. SIEM tool for monitoring and incident management
Knowledge/trained on any one of the cyber security tools like Web Application Firewall, Data Loss Prevention, Anti-APT, EDR etc.
Knowledge on security best practices and understanding of cyber security concepts
Cyber Security certification like CEH/OSCP/Any other equivalent is preferable.
Self-motivated and able to work on critical tasks independently and as a member of a team.