16 Aug
|
Tata Consultancy Services
|
Delhi
16 Aug
Tata Consultancy Services
Delhi
Key Responsibilities
1. Monitoring &
- Offense Management
- Monitor security events and alerts through QRadar dashboards, consoles, and offense queues.
- Conduct initial and detailed investigation of offenses, determine true/false positives, and escalate as required.
- Perform log enrichment, event correlation analysis, and offense deep‑dive using QRadar tools.
2. Investigation &
- Incident Response
- Investigate suspicious activities (credential misuse, lateral movement, DNS anomalies, exfiltration, malware behavior).
- Perform root‑cause analysis (RCA) for confirmed incidents.
- Document incident timelines, artifacts, and technical findings in SOC case management tools.
- Coordinate containment, eradication, and recovery steps with relevant teams.
3. AQL Search &
- Log Analysis
- Use AQL (Ariel Query Language) for advanced searches, pivoting, and correlation.
- Analyze logs from Windows/Linux servers, network devices, EDR, cloud services, and applications.
- Build actionable dashboards and custom queries to support threat‑hunting and investigations.
4.
Use Case
Management &
- Rule Tuning
- Review and tune QRadar correlation rules, building blocks, reference sets,
and threat models.
- Optimize detection rules to reduce false positives and improve alert fidelity.
- Work with Threat Intelligence team to integrate IOCs, threat feeds, and enrichment sources.
5.
Threat
Hunting
- Conduct proactive hunts using QRadar events, anomalies, traffic patterns, and baselines.
- Look for MITRE ATT&CK; TTPs such as privilege escalation, persistence, lateral movement, and command‑and‑control communication.
- Document hunt hypotheses, results, and recommended improvements.
6. QRadar Administration Support (as needed)
- Validate log source onboarding and troubleshoot ingestion issues.
- Ensure log sources are normalized, parsed correctly, and categorized appropriately.
- Participate in QRadar patching, upgrades, backup/restore tests, and HA validation (if required).
7. Reporting &
- Compliance
- Generate daily, weekly, and monthly security reports.
- Provide data for compliance audits (ISO 27001, PCI‑DSS, RBI, GDPR, internal governance).
Maintain all SOC documentation, SOPs, and detection playbooks.
📌 MDR (Delhi)
🏢 Tata Consultancy Services
📍 Delhi