SeniorAdministrator - Security Analysis, SIEM (India)

SeniorAdministrator - Security Analysis, SIEM (India)

24 Aug
|
HCLTech
|
India

24 Aug

HCLTech

India

Chennai, Tamil Nadu
Job Summary
Key Responsibilities Incident Detection & Response • Monitor and investigate security alerts from Taegis, Defender as well as user or third-party reported incidents. • Perform initial triage and analysis of suspicious events and potential security incidents. • Determine incident severity, scope, and business impact. • Contain security incidents through actions such as: o Account disablement o Password resets o Session revocation o Device isolation o IP and domain blocking • Escalate complex or high-severity incidents to senior security personnel. Investigation & Analysis • Analyze endpoint, network, identity, and cloud telemetry. • Correlate indicators of compromise (IOCs) with threat intelligence sources. • Identify root causes and attack vectors. • Conduct malware investigations and support forensic analysis activities. • Track attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK;. Incident Documentation • Maintain detailed incident records and case documentation. • Create incident reports detailing findings, actions taken, and business impact. • Ensure evidence is collected, preserved, and documented appropriately. • Participate in post-incident reviews and lessons-learned sessions. Collaboration • Coordinate with IT Operations, Service Desk, Infrastructure, Network, and Cloud teams during investigations. • Communicate incident status to stakeholders and management. • Support major incident response activities and virtual war room operations during significant security events. Continuous Improvement • Contribute to development of SOC playbooks and response procedures. • Recommend improvements to detection rules, monitoring coverage, and response workflows. • Assist in threat hunting and security control validation activities. • Stay current with emerging threats, vulnerabilities, and industry best practices. Required Qualifications Education • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or equivalent experience. Experience • 2–5+ years of cybersecurity, SOC, incident response, or security operations experience. • Experience investigating security incidents in enterprise environments. • Familiarity with Windows, Linux, cloud platforms, and enterprise networking. Technical Skills • SIEM technologies • EDR/XDR platforms (Taegis , Microsoft Defender, CrowdStrike, SentinelOne, etc.) • Email security technologies • Identity platforms such as Active Directory and Entra ID
Key Responsibilities
Key Responsibilities Incident Detection & Response • Monitor and investigate security alerts from Taegis, Defender as well as user or third-party reported incidents. • Perform initial triage and analysis of suspicious events and potential security incidents. • Determine incident severity, scope, and business impact. • Contain security incidents through actions such as: o Account disablement o Password resets o Session revocation o Device isolation o IP and domain blocking • Escalate complex or high-severity incidents to senior security personnel. Investigation & Analysis • Analyze endpoint, network, identity, and cloud telemetry. • Correlate indicators of compromise (IOCs) with threat intelligence sources. • Identify root causes and attack vectors. • Conduct malware investigations and support forensic analysis activities. • Track attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK;. Incident Documentation • Maintain detailed incident records and case documentation.



• Create incident reports detailing findings, actions taken, and business impact. • Ensure evidence is collected, preserved, and documented appropriately. • Participate in post-incident reviews and lessons-learned sessions. Collaboration • Coordinate with IT Operations, Service Desk, Infrastructure, Network, and Cloud teams during investigations. • Communicate incident status to stakeholders and management. • Support major incident response activities and virtual war room operations during significant security events. Continuous Improvement • Contribute to development of SOC playbooks and response procedures. • Recommend improvements to detection rules, monitoring coverage, and response workflows. • Assist in threat hunting and security control validation activities. • Stay current with emerging threats, vulnerabilities, and industry best practices. Required Qualifications Education • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or equivalent experience. Experience • 2–5+ years of cybersecurity, SOC, incident response, or security operations experience. • Experience investigating security incidents in enterprise environments. • Familiarity with Windows, Linux, cloud platforms, and enterprise networking. Technical Skills • SIEM technologies • EDR/XDR platforms (Taegis , Microsoft Defender, CrowdStrike, SentinelOne, etc.) • Email security technologies • Identity platforms such as Active Directory and Entra ID

Skill Requirements
: Key Responsibilities Incident Detection & Response • Monitor and investigate security alerts from Taegis, Defender as well as user or third-party reported incidents. • Perform initial triage and analysis of suspicious events and potential security incidents. • Determine incident severity, scope, and business impact. • Contain security incidents through actions such as: o Account disablement o Password resets o Session revocation o Device isolation o IP and domain blocking • Escalate complex or high-severity incidents to senior security personnel. Investigation & Analysis • Analyze endpoint, network, identity, and cloud telemetry. • Correlate indicators of compromise (IOCs) with threat intelligence sources. • Identify root causes and attack vectors. • Conduct malware investigations and support forensic analysis activities. • Track attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK;. Incident Documentation • Maintain detailed incident records and case documentation. • Create incident reports detailing findings, actions taken, and business impact. • Ensure evidence is collected, preserved, and documented appropriately. • Participate in post-incident reviews and lessons-learned sessions. Collaboration • Coordinate with IT Operations, Service Desk, Infrastructure, Network, and Cloud teams during investigations. • Communicate incident status to stakeholders and management. • Support major incident response activities and virtual war room operations during significant security events. Continuous Improvement • Contribute to development of SOC playbooks and response procedures. • Recommend improvements to detection rules, monitoring coverage,



and response workflows. • Assist in threat hunting and security control validation activities. • Stay current with emerging threats, vulnerabilities, and industry best practices. Required Qualifications Education • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or equivalent experience. Experience • 2–5+ years of cybersecurity, SOC, incident response, or security operations experience. • Experience investigating security incidents in enterprise environments. • Familiarity with Windows, Linux, cloud platforms, and enterprise networking. Technical Skills • SIEM technologies • EDR/XDR platforms (Taegis , Microsoft Defender, CrowdStrike, SentinelOne, etc.) • Email security technologies • Identity platforms such as Active Directory and Entra ID

Other Requirements
Responsibilities Incident Detection & Response • Monitor and investigate security alerts from Taegis, Defender as well as user or third-party reported incidents. • Perform initial triage and analysis of suspicious events and potential security incidents. • Determine incident severity, scope, and business impact. • Contain security incidents through actions such as: o Account disablement o Password resets o Session revocation o Device isolation o IP and domain blocking • Escalate complex or high-severity incidents to senior security personnel. Investigation & Analysis • Analyze endpoint, network, identity, and cloud telemetry. • Correlate indicators of compromise (IOCs) with threat intelligence sources. • Identify root causes and attack vectors. • Conduct malware investigations and support forensic analysis activities. • Track attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK;. Incident Documentation • Maintain detailed incident records and case documentation. • Create incident reports detailing findings, actions taken, and business impact. • Ensure evidence is collected, preserved, and documented appropriately. • Participate in post-incident reviews and lessons-learned sessions. Collaboration • Coordinate with IT Operations, Service Desk, Infrastructure, Network, and Cloud teams during investigations. • Communicate incident status to stakeholders and management. • Support major incident response activities and virtual war room operations during significant security events. Continuous Improvement • Contribute to development of SOC playbooks and response procedures. • Recommend improvements to detection rules, monitoring coverage, and response workflows. • Assist in threat hunting and security control validation activities. • Stay current with emerging threats, vulnerabilities, and industry best practices. Required Qualifications Education • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or equivalent experience. Experience • 2–5+ years of cybersecurity, SOC, incident response, or security operations experience. • Experience investigating security incidents in enterprise environments. • Familiarity with Windows, Linux, cloud platforms, and enterprise networking. Technical Skills • SIEM technologies • EDR/XDR platforms (Taegis , Microsoft Defender, CrowdStrike, SentinelOne, etc.) • Email security technologies • Identity platforms such as Active Directory and Entra ID
#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-

📌 SeniorAdministrator - Security Analysis, SIEM (India)
🏢 HCLTech
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senioradministrator - security analysis, siem (india) / india

Subscribe to this job alert:

Get the latest job offers by email for: senioradministrator - security analysis, siem (india) / india