20 Aug
|
Zensar
|
Hyderabad
Key Responsibilities
Security Monitoring Incident Detection (Must have)
Monitor security events and alerts generated from Logpoint SIEM (GuardSIX) and integrated security tools.
Perform real-time analysis of security incidents and suspicious activities.
Investigate alerts related to malware, phishing, ransomware, insider threats, privilege misuse, and unauthorized access.
Validate and triage security alerts based on severity and business impact.
Escalate incidents to L2 L3 teams and stakeholders as per defined procedures.
Incident Response Investigation (Must Have)
Conduct incident investigations using SIEM queries and threat intelligence sources.
Analyze logs from:
o Windows Servers Workstations
o Linux Systems
o Active Directory
o Firewalls
o IDS/IPS
o Proxy and Web Gateways
o EDR/XDR Solutions
o Cloud Platforms (Azure, AWS, GCP)
Perform root cause analysis and incident documentation.
Support containment, eradication, and recovery activities.
Threat Hunting Threat Intelligence (Must have)
Execute proactive threat hunting activities using Logpoint searches.
Leverage MITRE ATTCK framework for threat mapping.
Analyze Indicators of Compromise (IoCs).
Correlate threat intelligence feeds with internal security events.
Identify anomalous user and system behaviors.
Logpoint SIEM Administration Use Case Monitoring (Valuable to have)
Create, modify, and tune Logpoint correlation rules and use cases.
Fine-tune alert thresholds to reduce false positives.
Develop dashboards, reports, and custom searches.
Monitor log collection health and data ingestion.
Validate parser functionality and troubleshoot log collection issues.
Perform use case validation and testing.
Required Technical Skills
SIEM
Hands-on experience with:
o Logpoint SIEM (GuardSIX) Mandatory
o Experience with Splunk/QRadar/Microsoft Sentinel (Preferred)
Security Technologies
Firewalls (Palo Alto, Fortinet, Check Point, Cisco)
IDS/IPS (Snort, Suricata, Trend Micro)
EDR/XDR (Micr
📌 DIGITAL SECURITY (Hyderabad)
🏢 Zensar
📍 Hyderabad