09 Aug
|
wNy Consulting
|
Bengaluru
09 Aug
wNy Consulting
Bengaluru
General Position Summary
As a key member of the Managed Services Security team a SOC Tier 3 Security Analyst will be the top technical expert in our 24x7x365 Security Operations Centre. This senior role handles complex security investigations, hunts for advanced threats, and drives continuous improvement of the MXDR service.
Key responsibilities include deep-dive analysis, developing threat detection strategies, leading major incident responses, and advising clients on security enhancements. The Tier 3 Security Analyst will possess deep expertise in Microsoft Sentinel and Defender XDR, along with forensic techniques, malware analysis, and attacker methodologies, is essential. The role also requires strong consulting and communication skills, offering a significant prospect to influence the MXDR service's evolution and appeal to senior experts motivated by innovation.
National in scope and local in focus, MNP is one of Canada’s largest professional service firms providing client-focused accounting, consulting, tax, and digital services to clients. Founded in 1958, MNP today is a CAD 2 billion+ organization with 9600+ employees and 154 offices across Canada.
MNP prides itself on being an ‘advisor’ to its clients (individuals, businesses, and organizations), focusing on their success by delivering personalized strategies and solutions that help clients reach their full potential — wherever business takes them.
MNP set up MNP SPARK its GCC in Bangalore in May 2025 with a focus on enabling the firm to drive growth, efficiency, customer delight and innovation, by leveraging high quality talent in India. MNP Spark is like any other MNP region/office - front facing, client focused but working with all MNP regions in Canada to deliver services.
DIGITAL is the fastest growing service line of MNP and focuses on enabling customers to define build and manage their digital journey. It focuses on enabling the right technology solutions to drive business outcomes for its clients. Digital at MNP Spark is focused on building the core competencies across the technology spectrum to help drive the firm’s Digital Agenda.
Responsibilities
- Conduct highly complex security incident investigations and deep-dive security analysis across endpoints (memory, disk), network traffic, and cloud environments (Azure, Microsoft 365).
- Develop and execute proactive campaigns using advanced KQL queries, integrated threat intelligence, and behavioral analysis techniques within Microsoft Sentinel and Microsoft Defender XDR platforms.
- Research, design, and implement novel threat detection logic, complex Analytics Rules and custom threat intelligence integrations in Microsoft Sentinel.
- Architect, build, test,
and maintain sophisticated playbooks using Azure Logic Apps to automate complex response actions and streamline SOC workflows.
- Serve as the ultimate escalation point for critical security incidents.
- Perform static and dynamic malware analysis, reverse engineering exploit techniques, and analyze adversary tactics, techniques, and procedures (TTPs).
- Actively drive the continuous improvement of the MXDR platform, including evaluating new tools, proposing architectural enhancements, refining processes, and enhancing detection capabilities based on threat landscape evolution and operational insight
- Function as a trusted security advisor to MNP Digital clients, delivering expert recommendations on security posture improvements, vulnerability remediation, threat mitigation strategies, and post-incident recovery plans.
- Present complex technical findings, investigation results and strategic recommendations to diverse audiences.
- Mentor Tier 1 and Tier 2 Security Analysts through knowledge sharing, training, and collaborative investigation.
- Work closely with SOC Security Architects on platform design, integration challenges, and strategic roadmap development.
- Maintain expert-level knowledge of cybersecurity landscape including emerging threats, attack vectors, defensive strategies, and Microsoft's security portfolio.
Requirements
Skills -
- § 6+ years in advanced SOC roles, Incident Response, Threat Hunting, or Cyber Threat Intelligence, handling complex investigations and proactive defense.
- Expert-level mastery of Microsoft Sentinel: Advanced KQL for complex hunting and analytics, custom detection rule engineering, SOAR playbook architecture and development (Azure Logic Apps), threat intelligence platform integration and utilization
- Expert-level understanding and extensive hands-on application of the full Microsoft Defender XDR suite (Endpoint, Identity, Office 365, Cloud Apps) for deep-dive investigations, proactive hunting, configuration, and advanced response actions.
- Strong practical experience with digital forensics methodologies and tools for endpoint (Windows, Linux, macOS), memory, and network forensic analysis.
- Experience with malware analysis techniques (static/dynamic) and reverse engineering concepts.
- Proven ability to develop and execute sophisticated,
hypothesis-driven threat hunting campaigns yielding tangible results.
- Deep understanding of adversary TTPs, cyber kill chain methodologies, and expert-level application of frameworks like MITRE ATT&CK; and D3FEND.
- Proficiency in scripting languages (e.g., Python, PowerShell) for security analysis, automation, tool development, and data manipulation.
- In-depth knowledge of Microsoft Azure security services (Defender for Cloud, Network Security Groups, Azure Firewall, Azure Policy) and Microsoft Entra ID security features (Identity Protection, Conditional Access, PIM).
- Familiarity with data protection concepts and tools, with exposure to Microsoft Purview being advantageous.
- Ability to present complex technical findings and recommendations to various stakeholders.
- Identifying and driving improvements in security tools, detection capabilities, and operational processes within a SOC or IR team.
- Exceptional skills in unraveling complex, multi-stage attacks.
- Superior written, verbal, and presentation skills for diverse audiences.
- Strong technical presence and mentoring capabilities.
- High initiative and ownership in tackling technical challenges.
- Focus on long-term threat detection improvement.
- Excellent communication skills, especially under high-pressure scenarios.
- Effective advisory, consulting, and relationship-building skills.
Educational Qualifications
Bachelor of Technology/Engineering Or Bachelor/Master’s in Computer Application
Certifications –
- Highly Desirable: Possession of advanced, industry-recognized security certifications such as:
- GIAC Certified Forensic Analyst (GCFA)
- GIAC Certified Incident Handler (GCIH)
- Certified Information Systems Security Professional (CISSP)
- Offensive Security Certified Professional (OSCP) or similar penetration testing certifications.
- Required or Strongly Preferred: Relevant Microsoft expert-level or advanced certifications, demonstrating mastery of the core platform, such as:
- Microsoft Certified: Cybersecurity Architect Expert (SC-100) OR
- Microsoft Certified: Security Operations Analyst Associate (SC-200) combined with demonstrable expert-level skills and experience.
- Microsoft Certified: Azure Security Engineer Associate (AZ-500) is highly relevant and valued.
Experience – 6+ Years as a SOC Security Analyst
Additional Information-
This position involves working 12-hour shifts on a rotating schedule. You will work from 7am to 7pm or 7pm to 7am for four days straight, followed by four days off. This schedule includes night shifts, weekends, and holidays to maintain continuous security coverage.
📌 SOC Security Tier3 Analyst, Digital (Bengaluru)
🏢 wNy Consulting
📍 Bengaluru