06 Aug
|
DATAMARK
|
Chennai
As an Information Security Analyst III, you are the senior member of the Information Security Team and the primary owner of DATMARK's most significant security work. Your main focus is leading the response to all High and Critical severity tickets and incidents, drawing from "hands-on" incident response experience to contain, eradicate, and recover from threats. You are responsible for implementing new Information Security controls and for the ongoing maintenance and upkeep of existing ones.
You oversee the work of the Information Security Analyst I and II, mentoring and developing the team, with particular focus on growing the Analyst I while recommending risk mitigation solutions based on audit findings and threat intelligence to continuously strengthen DATAMARK's security posture.
Primary Responsibilities: Systems Management and Technical Support (80%)
Serves as the primary responder and owner for all High and Critical severity tickets and incidents
Leads Incident Response end to end; applying hands-on Incident Response experience to contain, eradicate, and recover from incidents, and conducts post-incident reviews and lessons learned
Responsible for the implementation of new Information Security controls, from evaluation and design through deployment and validation
Responsible for the ongoing maintenance, upkeep, and tuning of existing information security controls
Collaborate with the Director of Information Security on Security Architecture, standards, and the Security Roadmap
Oversees all Information Security Analyst I and II tasks, and assists, mentors, and develops the team with particular focus on growing the Analyst I
Continuously analyzes all organizational systems and reviews daily threat intelligence to identify and prioritize risk
Reviews and prioritizes vulnerability findings and drives remediation with the Information Security Analyst I/II and the IT Team through to closure
Recommends risk mitigation solutions based on audit findings and threat intelligence
Evaluates, pilots, and recommends new security tooling and technologies
Maintains and reports on security and compliance metrics monthly
Develops and maintains incident response playbooks, runbooks, and standard operating procedures
Assists in reviewing and assessing technical deployments for risk before company-wide implementation and ensures compliance with security standards
Administers, supports, and maintains enterprise IT security systems, including troubleshooting and remediation of complex system issues
Works with the IT Team to provide timely, effective support and maintains system documentation, including network and data flow diagrams As the Senior owner (covering architecture, system maintenance and escalation) the Information Security Analyst III is responsible for the following security platforms and audits, with day-to-day operation performed by the Information Security Analyst I and II: SIEM/MDR (Security Information and Event Management) (Managed Detection Response)
Regularly verify that all configured log sources (firewalls, servers, intrusion detection systems, etc.)
send logs to the SIEM without errors
Fine-tune existing correlation rules to reduce false positives and improve the accuracy of threat detection. This involves analyzing alerts, adjusting thresholds, and refining rule logic
Investigate suspicious events and security incidents identified by the SIEM, using the available log data and other information to determine the root cause and scope of the issue
Follow established incident response procedures to contain, eradicate, and recover from security incidents
PAM (Privileged Access Management)
Maintain and update Privileged Access Management at the Application Level
Maintain the use of Privileged Accounts
Monitor abuse attempts of standard and Privileged Accounts
DLP (Data Loss Prevention) Management
Regularly review alerts to identify potential data breaches or policy violations
Fine-tune policies to minimize false positives and negatives
Create new policies to address emerging threats and data protection needs
Monitor system performance and resource utilization to ensure optimal operation
NAC (Network Access Control) Management
Continuously monitor the NAC system dashboard for any alerts, alarms, or suspicious activities. This includes failed authentication attempts, unauthorized access attempts, and devices violating security policies
Investigate and respond to NAC alerts promptly. Follow established incident response procedures to contain and mitigate any security incidents
Ensure consistent enforcement of NAC policies across the network. Regularly audit policy configurations to verify effectiveness and identify potential gaps
Monitor the overall health and performance of the NAC system. Check system resources, database integrity, and software updates
Work with IT teams, system owners, and other stakeholders to implement remediation plans. This may involve patching systems, updating software, changing configurations, or implementing workarounds
NDR (Network Detection and Response) Management
Monitor for unusual traffic spikes, unexpected connections, or communication with known malicious IPs/domains
Investigate any events that seem suspicious or unusual
Fine-tune model settings and thresholds to better align with Datamark's risk tolerance
Regularly check system health and performance to ensure it is operating optimally
Microsoft Entra ID (working knowledge)
Maintain working knowledge of identity and access configuration, conditional access policies, and sign-in/audit logging in Microsoft Entra ID
Cisco Secure Access (working knowledge)
Maintain working knowledge of Cisco Secure Access (SSE) policy, secure connectivity, and access enforcement
Universal SSO (working knowledge)
Maintain working knowledge of Universal Single Sign-On integrations and authentication flows for enterprise applications
Micro-Segmentation (working knowledge)
Maintain working knowledge of network micro-segmentation design and policy enforcement to limit lateral movement
CSPM (working knowledge)
Maintain working knowledge of Cloud Security Posture Management (CSPM) findings, misconfigurations, and overall cloud compliance posture
Ai Security (working knowledge)
Maintain working knowledge of best practices to secure in house applications using Ai, external LLMs and Autonomous Agents. This includes working with the Director of Information Security to create an internal framework to properly secure how an agent connects from MCP Servers to APIs
May also be responsible for any upcoming technical controls that may be implemented
Compliance and Governance (10%)
Create and remediate any incidents found during the technical control review process
Verify that assigned controls are working within agreed upon SLAs and vendor specifications
Works independently to follow established security protocols to safeguard the organization's IT infrastructure
Works independently to ensure compliance with relevant Security Frameworks and Regulations from CIS and NIST CSF to PCI, SOC 2 Type II, and ISO 27001
Administrative Duties (10%)
Responsible for creating and updating Standard Operating Procedures
Maintain assigned technical control documentation
Create current documentation or procedures per the direction of the Director of Information Security
Provide guidance and support to the Information Security Analyst I and II
Willingness to travel to DATAMARK global sites as necessary Requirements Minimum Qualifications: Education Requirements:
Bachelor's degree in Computer Science or related field, field experience in lieu of degree can be considered
Field Experience
At least five years of experience in Information Security
Position Experience
At least 1 year of experience in a senior or lead Information Security Analyst role, including hands-on incident response (detection, containment, eradication, and recovery)
Demonstrated experience with traditional vulnerability analysis: identifying, categorizing, prioritizing, tracking, and validating remediation of known vulnerabilities by accountable IT teams
Other Qualifications
One or more of the following: ISC2 CISSP (Certified Information Systems Security Professional) is highly preferred ISC2 CCSP (Certified Cloud Security Professional) GIAC GCIH (Certified Incident Handler) CompTIA CASP+ (Advanced Security Practitioner) ISACA CISA (Certified Information Systems Auditor) Required Skills: Extremely organized and detail oriented Capable of holding team members accountable to timely delivery of audit evidences
Practices and methods of IT strategy, enterprise architecture and security architecture
Excellent analytical and problem-solving abilities to identify and remediate security risks
Team-work mentality to develop security solutions in collaboration with other IT professionals Benefits Bundle of Benefits as follow; PF Gratuity Mediclaim
📌 Information Security Analyst III (Chennai)
🏢 DATAMARK
📍 Chennai