Description
- Actively monitoring, analysing & escalating SIEM alerts based on correlation rules,
- Email protection alerts & malware analysis,
- Provide inputs for proactive content fine tuning & use case enablement,
- Active threat hunting on network flow, user behaviour & threat intelligence,
- Phishing email analysis for MFs,
- Raising incidents in Pastebin inte
- Should be familiar with Domain Knowledge (Cyber Security), Threat Hunting, SIEM- Azure Sentinel, SIEM - (RSA / Splunk / LogRhythm), Python Scripting, Windows Active Directory, Operating systems and servers.
- Ability to Triage and assignment Incident Handling.
- Ability to Follow Playbooks instructions- Incident Response Playbooks
- Ability to Comprehend Logs (HTTP, SMTP, Network) (Under guidance)
- Understand and imbibe current SOC process
- Perform quality assessment on SOC operations being performed as per existing process
- Record and deviations identified into tracking tool(s)/spreadsheets
- Perform follow-ups with respective error owners to mitigate process deviations
- Identify process deviations,
Summarize and generate trends, patterns into process deviations / errors observed.
- Perform RCA into observed errors / trends and generate recommendations for process improvement
- Generate personnel specific recommendations for performance enhancement
- Contribute in overseeing quality assessment process for multiple SOC verticals
- In-line alignment with SOC operations for quick-detection / prevention of process deviations
- Support as QA touchpoint in critical cyber incidents to enhance quality of service
- Assessment of investigation report with assertions, evidences and recommended actions
- BE/B.Tech/Post-Grad/ Graduate or Postgraduate in any other discipline
- 0-2 years of relevant experience.
- Candidates should be okay to work in rotational shifts.
- Valuable to have - Certifications - CSA (Certified SoC Analyst), CISM and CCSP, Certifications from Microsoft Azure Suite
- Candidates having SOC ex