06 Aug
|
Deloitte Shared Services India
|
Mumbai
06 Aug
Deloitte Shared Services India
Mumbai
Role & responsibilities
- Investigate security alerts escalated by SOC L1 using SIEM, EDR, XDR, UEBA, NDR, Email Security, and other security platforms.
- Perform in-depth analysis of security events to determine scope, impact, and root cause.
- Validate true positives and eliminate false positives through detailed log analysis.
- Classify incidents based on severity and business impact.
- Execute containment, eradication, and recovery activities as per incident response procedures.
- Escalate complex incidents to L3 or Incident Response teams when required.
- Analyze indicators of compromise (IOCs) including IPs, URLs, domains, file hashes, and email artifacts.
- Correlate events across multiple security technologies to identify sophisticated attacks.
- Identify malicious behavior using the MITRE ATT&CK; framework and Cyber Kill Chain.
- Investigate phishing, malware, ransomware, insider threats, privilege misuse, and suspicious authentication activities.
- Perform endpoint investigations using EDR/XDR platforms.
Required Skills
- SIEM technologies (QRadar, Splunk, Sentinel, Chronicle)
- EDR/XDR solutions (CrowdStrike, Cortex XDR, Microsoft Defender)
- SOAR platforms
- Windows and Linux security
- Active Directory
- Network Security
- Firewalls
- DNS
- Proxy
Should be available to join with 30 days.
📌 Soc Analyst (Mumbai)
🏢 Deloitte Shared Services India
📍 Mumbai