13 Aug
|
Tata Communications
|
Hyderabad
13 Aug
Tata Communications
Hyderabad
Job Title: NG SIEM Analyst L2
Location: Client Location, Hyderabad
Experience Required:
- Minimum 7+ years of relevant experience with BCA/BSc-IT
- Or minimum 5+ years of relevant experience with B.E./B.Tech/MCA
Certifications Preferred: CEH, ArcSight Admin SIEM product certifications
Role Overview:
We are looking for an experienced L2 NG SIEM Analyst to support the day-to-day operations of our Next-Gen SIEM environment (SIEM + SOAR + UEBA). The candidate will be responsible for monitoring dashboards, responding to alerts, performing preliminary investigations, and supporting integrations and routine operational tasks under the guidance of L3 resources.
Key Responsibilities:
- Monitor NG SIEM (SIEM + SOAR + UEBA) consoles, dashboards, and alerts; provide timely responses to security incidents.
- Assist in incident triage, classification, and escalation to L3 team based on severity.
- Perform preliminary analysis of security events and provide recommendations for closure or mitigation.
- Support the integration of log sources such as firewalls, endpoint security tools, AD, WAF, antivirus, patch management tools, ERP systems, and custom applications.
- Monitor health status of system components and raise issues to L3 team when necessary.
- Assist in the creation and fine-tuning of use cases/playbooks/reports and alert rules under the guidance of the L3 team.
- Support custom parser and connector development in collaboration with the L3 team.
- Work with L3 team on reducing false positives by reviewing correlation rules and configurations.
- Follow Standard Operating Procedures (SOPs) and assist in documentation updates.
- Support the onboarding of new log sources and data validation post-integration.
- Provide timely support for access-related requests and permissions within the NG SIEM solution.
- Perform routine tasks such as backup monitoring, report generation, and compliance checks.
- Participate in Cyber Drills and tabletop exercises as part of continuous learning and SOC readiness.
- Maintain audit and incident logs as per company policy and assist during audits with required data and documentation.
- Stay updated on cyber threat trends and assist in implementing recommendations for improved detection and response.
- Escalate unresolved technical issues to the L3 team and support troubleshooting under guidance.
Required Skills:
- Strong working knowledge of at least one NG SIEM platform (ArcSight).
- Familiarity with SOAR and UEBA concepts and basic operational understanding.
- Basic experience in writing and managing correlation rules, alerts, and queries.
- Understanding of threat intelligence and incident response lifecycle.
- Familiarity with MITRE ATT&CK; and NIST frameworks.
- Hands-on experience with security logs from Windows/Linux servers, network devices, security appliances, and cloud infrastructure.
- Working knowledge of scripting or regex is a plus.
- Good analytical, documentation, and communication skills.
Soft Skills:
- Excellent problem-solving and troubleshooting skills.
- Ability to work under pressure and meet deadlines.
- Strong team collaboration and willingness to learn from senior team members.
- Solid communication and incident documentation/reporting ability.
📌 Lead - Captive Operations (Hyderabad)
🏢 Tata Communications
📍 Hyderabad