We are seeking a highly skilled SOC Expert to join our energetic cybersecurity team. The ideal candidate will play a crucial role in monitoring, detecting, analysing, and responding to security incidents. Candidate requires a deep understanding of security operations and a proactive approach to threat management and hands on known technologies like Tenable VM / Qualys VM, SentinelOne EDR , IDS/IPS, VM / WAS Scanning and Reporting , Any firewall, SIEM configuration as well as managing the alerts.
Hands on Expertise:
- SOC Incident management.
- Understanding of EDR Tenable or SentinelOne Configuration/ whitelisting/ blocking.
- Reading security Logs.
- Any Security tool Integration with automation tool, alert system, ticketing system.
Key Responsibilities:
- Threat Monitoring: Continuously monitor security alerts and events using SIEM tools to detect potential threats and vulnerabilities.
- Incident Response: Lead incident response activities, including identification, containment, eradication,
and recovery from security incidents.
- Security Analysis: Conduct thorough investigations of security breaches and incidents, providing detailed analysis and reporting.
- Risk Assessment: Perform regular risk assessments and vulnerability assessments to identify security weaknesses and recommend mitigation strategies.
- Collaboration: Work closely with IT and other departments to ensure a comprehensive security posture and effective incident response.
- Documentation: Maintain and update incident response plans, playbooks, and standard operating procedures.
- Training & Mentoring: Provide training and mentorship to junior SOC analysts and other team members on security best practices and threat intelligence.
- Research & Development: Stay up-to-date with the latest security trends, threats, and technologies to enhance the SOC’s capabilities.
- KPI/ KRI: Providing Data for KPI / KRI to management.