- Work in a 24x7 Security Operation Centre (SOC) setting.
- Provide analysis and trending of security log data from various security devices.
- Coordinate incident response on a daily basis.
- Perform threat analysis to improve detection capabilities.
- Conduct forensic investigations and develop recovery plans.
- Develop and implement advanced defensive strategies and countermeasures.
- Engage in threat hunting to identify potential threats that may have bypassed defenses.
- Communicate effectively through written and visual documents for diverse audiences.
Requirements
- Minimum of 8 - 10 years of experience in Cybersecurity.
- At least 6 years of working in a Security Operations Center (SOC).
- Proficient in Incident Management and Response,
handling escalations.
- In-depth knowledge of security concepts such as cyber-attacks, threat vectors, and risk management.
- Knowledge of various operating system flavors including Windows, Linux, and Unix.
- Knowledge of TCP/IP protocols and network analysis.
- Experience with SIEM, SSL, Packet Analysis, HIPS/NIPS, and network monitoring tools.
Nice-to-haves
- Hands-on experience with Splunk.
- Experience with Proofpoint and Azure security.
- Ability to suggest fine-tuning of existing security use cases.