Role: SOC L2/L3 Location: Chennai and Noida Experience: 6+ Years Interview date: 8th August (Walkin – Face to Face) Address Noida: Tata Consultancy Services Limited, C - 56, Phase-II, NOIDA, UTTAR PRADESH-201305.
Chennai: TCS Ozone Techno Park, No. 1/13, Old Mahabalipuram Road (OMR), Navallur, Chennai - 603103 Roles and Responsibilities: Must-Have • Experience in Sentinel SIEM tool, Fine tuning of Rules.
- Knowledge of different Microsoft Defender products. Implementation and integration of defender for cloud services.
- Automation Rule creation along with creation of Playbooks, Workbooks.
- Leadership & Team management skills during their approved shifts.
- Experience in cloud computing and cloud security role.
- Experience in Azure security role.
- Experience in automation in SOC area.
- Minimum 5 years of experience in Microsoft Sentinel and Azure log analytics and developing Kusto Query Language Experience in SIEM and SOAR implementation.
- Should have experience in developing KQL queries for data normalization and parsing capability for Log Analytics data ingestion pipeline.
- Highly proficient in Microsoft Sentinel and Azure Log Analytics.
Valuable-to-Have • Microsoft Defender XDR/Endpoint/Microsoft Cloud App Security • Skills/knowledge in hypothesis-based threat hunting.
- Skills/knowledge in threat intelligence • Skills/knowledge in Recorded Future tool for Threat Intelligence. Responsibility of / Expectations from the Role 1 Proactively search for threats that may not trigger alerts, utilizing threat intelligence and advanced analytical skills. 2 Lead and coordinate responses to critical security incidents, including containment, eradication, and recovery. 3 Create and refine detection rules and security use cases for SIEM and other security tools. 4 Correlate data from threat intelligence feeds and other sources to identify emerging threats and vulnerabilities. 5 Investigate complex security incidents to determine the root cause and prevent future occurrences. 6 Maintain accurate and detailed records of incidents, investigations, and remediation steps. 7 Work with other teams, such as engineering and IT, to improve security posture and implement necessary changes. 8 Effectively communicate with stakeholders, including technical and non-technical personnel, about security incidents and status. 9 Able to connect any type of logs and from any type of source to Sentinel Log Analytic workspace.