07 Aug
|
Deloitte Shared Services India
|
Mumbai
07 Aug
Deloitte Shared Services India
Mumbai
Role & responsibilities
Investigate security alerts escalated by SOC L1 using SIEM, EDR, XDR, UEBA, NDR, Email Security, and other security platforms.
Perform in-depth analysis of security events to determine scope, impact, and root cause.
Validate true positives and eliminate false positives through detailed log analysis.
Classify incidents based on severity and business impact.
Execute containment, eradication, and recovery activities as per incident response procedures.
Escalate complex incidents to L3 or Incident Response teams when required.
Analyze indicators of compromise (IOCs) including IPs, URLs, domains, file hashes, and email artifacts.
Correlate events across multiple security technologies to identify sophisticated attacks.
Identify malicious behavior using the MITRE ATT&CK; framework and Cyber Kill Chain.
Investigate phishing, malware, ransomware, insider threats, privilege misuse, and suspicious authentication activities.
Perform endpoint investigations using EDR/XDR platforms.
Required Skills
SIEM technologies (QRadar, Splunk, Sentinel, Chronicle)
EDR/XDR solutions (CrowdStrike, Cortex XDR, Microsoft Defender)
SOAR platforms
Windows and Linux security
Active Directory
Network Security
Firewalls
DNS
Proxy
Should be available to join with 30 days.
📌 Soc Analyst Mumbai
🏢 Deloitte Shared Services India
📍 Mumbai