06 Aug
|
Armor Defense
|
Pune
06 Aug
Armor Defense
Pune
Armor is seeking an Incident Response and Security Operations Consultant (L2) to independently lead customer consultations on security incidents, threat analysis, and remediation strategy. Beyond incident response and security operations support, the L2 Consultant actively participates in projects that operationalize new customer-facing SOC capabilities, including vulnerability and exposure management, control validation, security technology management, data security, and policy management. This role mentors L1 Consultants, drives process improvement, contributes to the SOC knowledge base, and exercises direct detection tuning authority in support of Armor's expanding service model.
REQUIRED SKILLS
- Robust proficiency with security tools: EDR/XDR (Defender/Sentinel required, Trend and Crowdstrike preferred), SIEM (Sentinel, QRadar), SOAR, and threat intelligence platforms,
- Solid understanding of cloud security across Azure, AWS, and VMware including identity, networking, and workload protection.
- Forensic analysis skills including host triage, log analysis, and malware identification.
- Proficient in scripting (Python, PowerShell, KQL) for analysis, automation, and detection development.
- Proficiency with git version control including branching, commits, and pull request workflows.
- Experience using agentic AI tools (Claude, OpenAI Codex, or equivalent) to develop detection content, automate analysis, and build security tooling.
- Understanding of AI/LLM security risks; ability to critically evaluate AI-generated outputs for accuracy, security implications, and operational fitness.
- Working knowledge of vulnerability management, control validation, and security policy frameworks.
- Demonstrated mentoring and training ability.
- Strong customer consultation and advisory skills; comfortable leading engagements via video, phone, chat, and ticket in English.
- Ability to analyze complex attack chains and communicate findings to both technical and non-technical audiences.
- Ability to develop written deliverables including incident reports and remediation guidance.
EDUCATION AND/OR EXPERIENCE
- 3-5 years of experience in incident response, security consulting, or security operations; prior IR or consulting experience required.
- Required certifications within 12 months: AZ-500, SC-200, SC-300, SC-401.
- Certifications preferred: GCIH, GCFA, CySA+, CEH, or equivalent.
- Bachelors Degree in Information Technology, Cybersecurity, or related field preferred; equivalent experience accepted.
- Demonstrated commitment to ongoing professional development and continuing education.
WORK ENVIRONMENT
- The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. The noise level in the work environment is usually low to moderate. This is an in-office position based at one of our SOC locations.
Disclaimer : This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Incident Response and Security Operations Consultant (Pune)
🏢 Armor Defense
📍 Pune