06 Aug
|
CES Private
|
Secunderabad
06 Aug
CES Private
Secunderabad
Summary:We are seeking a highly skilled SOC Analyst with expertise in Splunk, SIEM tools, EDR solutions, vulnerability management, and automation scripting using Python and PowerShell. The successful candidate will be instrumental in detecting, responding to, and preventing security threats while optimizing security operations through automation and advanced threat detection techniques.Key Responsibilities:Security Operations & Incident Response:
- Monitor, analyse, and investigate security events using Splunk and other SIEM platforms.
- Respond to and remediate security incidents using established playbooks and best practices.
- Leverage EDR tools to detect and contain endpoint threats effectively.
- Conduct root cause analysis to identify and mitigate risks.
Splunk & SIEM Management:
- Configure, manage, and optimize Splunk dashboards, alerts, and log ingestion pipelines.
- Develop custom queries and detection rules to enhance monitoring capabilities.
- Generate actionable insights and reports from Splunk and SIEM systems for stakeholders.
Vulnerability Management:
- Perform vulnerability assessments using tools like Nessus, Qualys, or Tenable.
- Analyse and prioritize vulnerabilities based on risk and business impact.
- Coordinate with IT teams to ensure timely remediation of vulnerabilities and misconfigurations.
- Track and report on vulnerability trends and patch compliance.
Automation & Scripting:
- Develop and maintain automation scripts using Python and PowerShell to streamline SOC processes.
- Automate repetitive tasks such as log parsing,
threat detection, and vulnerability remediation.
- Integrate SIEM, EDR, and vulnerability management tools with orchestration platforms for end-to-end automation.
Threat Detection & Analysis:
- Proactively hunt for threats and analyse indicators of compromise (IOCs) and attacker techniques.
- Utilize threat intelligence to improve detection capabilities and inform incident response.
- Design and implement custom detection rules based on threat scenarios.
Reporting & Collaboration:
- Prepare detailed incident reports, vulnerability assessments, and remediation plans.
- Collaborate with IT and security teams to improve the organizations security posture.
- Provide insights and recommendations for enhancing security operations.
Qualifications & Skills:Education:
- Bachelor's Degree in Engineering/Technology (B.E., B.Tech) or related fields.
- Master's Degree (M.Tech, M.Sc., or equivalent) in Cybersecurity, Computer Science, or IT (preferred).
- UG/PG in a relevant discipline will also be considered.
Technical Skills:
- Hands-on experience with Splunk and other SIEM platforms.
- Proficiency in EDR solutions like CrowdStrike, Carbon Black, or Microsoft Defender.
- Robust understanding of vulnerability management processes and tools.
- Proficient in scripting languages: Python, PowerShell (automation experience is mandatory).
- Familiarity with threat intelligence platforms, detection engineering, and MITRE ATT&CK; framework.
- Experience with log analysis, alert management, and incident triage.
📌 SOC Analyst (Secunderabad)
🏢 CES Private
📍 Secunderabad