14 Aug
|
Bravura Solutions
|
Gurugram
14 Aug
Bravura Solutions
Gurugram
Role The Senior SOC Analyst is a senior technical member of the Security Operations team, responsible for leading complex security investigations and incident response across corporate and client hosting environments. The role proactively hunts for threats, acts as an escalation point, coordinates containment and recovery, and uses threat intelligence, digital forensics and security telemetry to determine the scope and impact of incidents. It also strengthens SOC capability through SIEM tuning, detection engineering, runbook development, vulnerability management and continuous improvement, while mentoring analysts and communicating clearly with customers, management and other stakeholders.
Main Activities
Threat hunting, proactively identifying previously unknown, or ongoing non-remediated threats.
SOC SIEM fine tuning and design improvements
Valuable understanding of, and working in alignment with the MITRE ATT&CK; framework
Applying OWASP standards and security best practices The Level 3 SOC Security Analyst is responsible for conducting information security investigations due to security incidents identified from various SOC entry channels (SIEM, Tickets, Email and Phone).
Act as a point of escalation in support of information security investigations to provide guidance and oversight on incident resolution and containment techniques.
Create and maintain SOC Run books for Both AWS Cloud hosting and corporate systems
Act as the lead coordinator for Bravura Solutions response to individual information security incidents.
Mentor security analysts regarding risk management, information security controls, incident analysis, incident response, SIEM monitoring, and other operational tasks in support of technologies managed by the Security Operations Centre.
Document incidents from initial detection through final resolution.
Participate in vulnerability management.
Participate in evaluating, recommending, implementing, and troubleshooting security solutions and evaluating IT security of the new IT Infrastructure systems.
Works as part of a team to ensure that corporate data and cloud hosting platform components are safeguarded from known threats.
Communicate effectively with customers, teammates, and management.
Prepare Monthly Executive Summary Reports for managed clients and continuously improve their content and presentation.
Provide recommendations in tuning and optimisation of security systems, SOC security process, procedures, and policies.
Define, create, and maintain SIEM correlation rules & customer build documents, security process and procedures.
Follow ITIL practices regarding incident, problem and change management.
Staying up to date with emerging security threats including applicable regulatory security requirements & AI
Other responsibilities and additional duties as assigned by the SOC Manager.
In addition to the above position-specific responsibilities, all employees are required to undertake any other reasonable duties and responsibilities within your capability and skills, when requested to do so.
Qualifications and Experience
Preferred Information Security professional designations such as CISSP, CISM, AWS Security Specialty, Microsoft Azure security certifications, or equivalent industry-recognized credentials
5+ years previous Security Operations Centre Experience in conducting security investigations.
Experience working in SOC Team responding to incidents and events in AWS cloud hosting is essential
Demonstrated skills in digital investigations including computer forensics, network forensics, malware analysis and memory analysis.
Must have advanced knowledge of, and experience with enterprise SIEM and vulnerability management platforms (Rapid7 InsightIDR and InsightVM preferred)
Must have hands on experience with managing EDR services in AWS nodes (EKS, EC2)
Must have knowledge of AWS cloud native services such as (SecurityHub, GuardDuty)
Ability to analyse data, such as logs or packets captures, from various sources within the enterprise and draw conclusions regarding past and future security incidents.
Detail oriented with strong organisational and analytical skills.
Strong written communication skills and presentation skills
Self-starter, work independently and adjust to changing priorities, critical and strategic thinker, negotiator, and consensus builder.
Strong knowledge of IT including multiple operating systems and system administration skills
Strong knowledge of client-server applications, multi-tier web applications, relational databases, firewalls, VPNs, and enterprise Anti-Virus products.
Strong understanding of security incident management, malware management and vulnerability management processes.
Experience with web content filtering technology - policy engineering and troubleshooting.
📌 Senior SOC Analyst (Gurugram)
🏢 Bravura Solutions
📍 Gurugram