22 Aug
|
Tekskills
|
Bengaluru
22 Aug
Tekskills
Bengaluru
- Primary mandate skill required
1. EDR platform management and optimization experience in tools :
- MS Defender and SentinelOne.
1. SIEM solution management and implementation in MS sentinel.
- Detection Engineering
- Log source management
- KQL logic and Defender Advanced hunting query building
- Logic App implementation
- SOAR playbook and use cases creation
- AIR implementation
- M365 Copilot Agent creation and implementation
- Dashboard creation and optimization
- Secondary mandate skill required Azure WAF, AWS WAF and F5 DCS WAF(Distributed cloud) – Configuration, maintenance, and optimization.
- Adaptable to hire in any location – If not, please mention job location – Chennai / Bangalore / Pune / Hyderabad
- Detailed – Attached the JD.
Should have minimum 10 - 12 years of experience in the following technologies and tools including MS Defender, MS Sentinel, MS Intune, MS Purview, SentinelOne, Cisco IDS/IPS, Checkpoint IDS/IPS, F5 DCS WAF. Experience in implementing, maintaining, and optimizing MS Purview DLP solutions will be positive to have.
Should have knowledge in Kusto query language; playbook & workbook creation and updation, logic app configuration in MS Sentinel.
Understanding of Linux, Windows, AD, Network, and security event logging.
In-depth understanding of security threats, threat attack methods and the current threat environment to develop detection use cases.
Ensure effective operation of SIEM content:
filters, rules, expressions and other identification mechanisms of the threat and vulnerability management technologies.
Provide professional data analysis to drive further security measures and risk mitigation activities.
Strong verbal and written interpersonal communication skills.
Willingness to work in US shift timings as required to support the team or at priority calls.
Completion of one or more certifications on the below is an added advantage: SC-200, SC-100, CCNA Security, AZ-500.
Primary skillset: Cyber Security Architect - ITM Engineering
Operational and Implementation hands-on expertise in
1. EDR platform management and optimisation experience in tools : MS Defender and SentinelOne.
2. SIEM solution management and implementation in MS sentinel.
Detection Engineering
Log source management
KQL logic and Defender Advanced hunting query building
Logic App implementation
SOAR playbook and use cases creation
AIR implementation
M365 Copilot Agent creation and implementation
Dashboard creation and optimisation
1. Azure WAF, AWS WAF and F5 DCS WAF(Distributed cloud) – Configuration, maintenance, and optimisation.
2. Checkpoint and Cisco Firepower IDS/IPS rules and signature fine tuning.
3. Perform Risk Assessment and provide recommendations to improve Security posture.
4. Prior experience in SOC and incident response.
📌 Itsm Lead (Bengaluru)
🏢 Tekskills
📍 Bengaluru