Chennai: TCS Ozone Techno Park, No. 1/13, Old Mahabalipuram Road (OMR), Navallur, Chennai - 603103
Roles and Responsibilities:
Must-Have
- Experience in Sentinel SIEM tool, Fine tuning of Rules.
- Knowledge of different Microsoft Defender products. Implementation and integration of defender for cloud services.
- Automation Rule creation along with creation of Playbooks, Workbooks.
- Leadership & Team management skills during their approved shifts.
- Experience in cloud computing and cloud security role.
- Experience in Azure security role.
- Experience in automation in SOC area.
- Minimum 5 years of experience in Microsoft Sentinel and Azure log analytics and developing Kusto Query Language Experience in SIEM and SOAR implementation.
- Should have experience in developing KQL queries for data normalization and parsing capability for Log Analytics data ingestion pipeline.
- Highly proficient in Microsoft Sentinel and Azure Log Analytics.
Valuable-to-Have
- Microsoft Defender XDR/Endpoint/Microsoft Cloud App Security
- Skills/knowledge in hypothesis-based threat hunting.
- Skills/knowledge in threat intelligence
- Skills/knowledge in Recorded Future tool for Threat Intelligence.
Responsibility of / Expectations from the Role
1 Proactively search for threats that may not trigger alerts, utilizing threat intelligence and advanced analytical skills.
2 Lead and coordinate responses to critical security incidents, including containment, eradication, and recovery.
3 Create and refine detection rules and security use cases for SIEM and other security tools.
4 Correlate data from threat intelligence feeds and other sources to identify emerging threats and vulnerabilities.
5 Investigate complex security incidents to determine the root cause and prevent future occurrences.
6 Maintain accurate and detailed records of incidents, investigations, and remediation steps.
7 Work with other teams, such as engineering and IT, to improve security posture and implement necessary changes.
8 Effectively communicate with stakeholders, including technical and non-technical personnel, about security incidents and status.
9 Able to connect any type of logs and from any type of source to Sentinel Log Analytic workspace.