- 4-7 years Information Security experience with at least 4+ year of Incident Response experience.
- Manage client engagements, with a focus on incident response and investigation. Provide both subject matter expertise and project management experience to serve as the point person for client engagements
- Assist with scoping prospective engagements, participating in engagements from kick-off through full remediation, and mentoring teams
- Assist clients in developing Incident Response Plan, Processes and playbooks.
- Recommend and document specific counter-measures and mitigating controls with post incident analysis findings
- Develop comprehensive and accurate reports and presentations for both technical and executive audiences
- Perform technical cybersecurity investigations on security incidents, root cause analysis, recommend and mitigate the effects caused by an incident
- Provide technical Incident Response guidance to the L1 and L2 incident response Analysts
- Mature the Security Incident Response process to ensure it meets the needs of the Clients
- Interact with Client’s CSIRT teams to cater continuous and/or adhoc client requests for Incident Response services
- Provide information security metrics and key performance indicators (KPI's). Participate in incident response and security operations Team.
- Involve in business development activities and supporting pre-sales teams in Identify, market, and develop current business opportunities
- Assist with research and distribute cyber threat intelligence developed from Incident Response activities.
- Understanding of Incident Response standards including investigation management experience
- Security Incident Process knowledge to help and guide SOC analysts and Engineers
- Location: Bangalore
Preferred candidate profile
- Strong understanding of the IR process and familiarity with known IR standards. Strong knowledge of host and network forensic tools and techniques.
- Understanding of Threat Hunting and threat Intelligence concepts and technologies. Industry certifications such as ECIH v2, CHFI, GCIH or GCIA along with experience will be a bonus. Experience in lieu of certification will be taken into consideration.
- Education: Bachelor’s degree in information security, Computer Science, or a related field. A master’s in business management is preferred.