Chennai, Tamil Nadu
Job Summary
Key Responsibilities Incident Detection & Response • Monitor and investigate security alerts from Taegis, Defender as well as user or third-party reported incidents. • Perform initial triage and analysis of suspicious events and potential security incidents. • Determine incident severity, scope, and business impact. • Contain security incidents through actions such as: o Account disablement o Password resets o Session revocation o Device isolation o IP and domain blocking • Escalate complex or high-severity incidents to senior security personnel. Investigation & Analysis • Analyze endpoint, network, identity, and cloud telemetry. • Correlate indicators of compromise (IOCs) with threat intelligence sources. • Identify root causes and attack vectors. • Conduct malware investigations and support forensic analysis activities. • Track attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK;. Incident Documentation • Maintain detailed incident records and case documentation. • Create incident reports detailing findings, actions taken, and business impact. • Ensure evidence is collected, preserved, and documented appropriately. • Participate in post-incident reviews and lessons-learned sessions. Collaboration • Coordinate with IT Operations, Service Desk, Infrastructure, Network, and Cloud teams during investigations. • Communicate incident status to stakeholders and management. • Support major incident response activities and virtual war room operations during significant security events. Continuous Improvement • Contribute to development of SOC playbooks and response procedures. • Recommend improvements to detection rules, monitoring coverage, and response workflows. • Assist in threat hunting and security control validation activities. • Stay current with emerging threats, vulnerabilities, and industry best practices. Required Qualifications Education • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or equivalent experience. Experience • 2–5+ years of cybersecurity, SOC, incident response, or security operations experience. • Experience investigating security incidents in enterprise environments. • Familiarity with Windows, Linux, cloud platforms, and enterprise networking. Technical Skills • SIEM technologies • EDR/XDR platforms (Taegis , Microsoft Defender, CrowdStrike, SentinelOne, etc.) • Email security technologies • Identity platforms such as Active Directory and Entra ID
Key Responsibilities
Key Responsibilities Incident Detection & Response • Monitor and investigate security alerts from Taegis, Defender as well as user or third-party reported incidents. • Perform initial triage and analysis of suspicious events and potential security incidents. • Determine incident severity, scope, and business impact. • Contain security incidents through actions such as: o Account disablement o Password resets o Session revocation o Device isolation o IP and domain blocking • Escalate complex or high-severity incidents to senior security personnel. Investigation & Analysis • Analyze endpoint, network, identity, and cloud telemetry. • Correlate indicators of compromise (IOCs) with threat intelligence sources. • Identify root causes and attack vectors. • Conduct malware investigations and support forensic analysis activities. • Track attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK;. Incident Documentation • Maintain detailed incident records and case documentation.
• Create incident reports detailing findings, actions taken, and business impact. • Ensure evidence is collected, preserved, and documented appropriately. • Participate in post-incident reviews and lessons-learned sessions. Collaboration • Coordinate with IT Operations, Service Desk, Infrastructure, Network, and Cloud teams during investigations. • Communicate incident status to stakeholders and management. • Support major incident response activities and virtual war room operations during significant security events. Continuous Improvement • Contribute to development of SOC playbooks and response procedures. • Recommend improvements to detection rules, monitoring coverage, and response workflows. • Assist in threat hunting and security control validation activities. • Stay current with emerging threats, vulnerabilities, and industry best practices. Required Qualifications Education • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or equivalent experience. Experience • 2–5+ years of cybersecurity, SOC, incident response, or security operations experience. • Experience investigating security incidents in enterprise environments. • Familiarity with Windows, Linux, cloud platforms, and enterprise networking. Technical Skills • SIEM technologies • EDR/XDR platforms (Taegis , Microsoft Defender, CrowdStrike, SentinelOne, etc.) • Email security technologies • Identity platforms such as Active Directory and Entra ID
Skill Requirements
: Key Responsibilities Incident Detection & Response • Monitor and investigate security alerts from Taegis, Defender as well as user or third-party reported incidents. • Perform initial triage and analysis of suspicious events and potential security incidents. • Determine incident severity, scope, and business impact. • Contain security incidents through actions such as: o Account disablement o Password resets o Session revocation o Device isolation o IP and domain blocking • Escalate complex or high-severity incidents to senior security personnel. Investigation & Analysis • Analyze endpoint, network, identity, and cloud telemetry. • Correlate indicators of compromise (IOCs) with threat intelligence sources. • Identify root causes and attack vectors. • Conduct malware investigations and support forensic analysis activities. • Track attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK;. Incident Documentation • Maintain detailed incident records and case documentation. • Create incident reports detailing findings, actions taken, and business impact. • Ensure evidence is collected, preserved, and documented appropriately. • Participate in post-incident reviews and lessons-learned sessions. Collaboration • Coordinate with IT Operations, Service Desk, Infrastructure, Network, and Cloud teams during investigations. • Communicate incident status to stakeholders and management. • Support major incident response activities and virtual war room operations during significant security events. Continuous Improvement • Contribute to development of SOC playbooks and response procedures. • Recommend improvements to detection rules, monitoring coverage,
and response workflows. • Assist in threat hunting and security control validation activities. • Stay current with emerging threats, vulnerabilities, and industry best practices. Required Qualifications Education • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or equivalent experience. Experience • 2–5+ years of cybersecurity, SOC, incident response, or security operations experience. • Experience investigating security incidents in enterprise environments. • Familiarity with Windows, Linux, cloud platforms, and enterprise networking. Technical Skills • SIEM technologies • EDR/XDR platforms (Taegis , Microsoft Defender, CrowdStrike, SentinelOne, etc.) • Email security technologies • Identity platforms such as Active Directory and Entra ID
Other Requirements
Responsibilities Incident Detection & Response • Monitor and investigate security alerts from Taegis, Defender as well as user or third-party reported incidents. • Perform initial triage and analysis of suspicious events and potential security incidents. • Determine incident severity, scope, and business impact. • Contain security incidents through actions such as: o Account disablement o Password resets o Session revocation o Device isolation o IP and domain blocking • Escalate complex or high-severity incidents to senior security personnel. Investigation & Analysis • Analyze endpoint, network, identity, and cloud telemetry. • Correlate indicators of compromise (IOCs) with threat intelligence sources. • Identify root causes and attack vectors. • Conduct malware investigations and support forensic analysis activities. • Track attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK;. Incident Documentation • Maintain detailed incident records and case documentation. • Create incident reports detailing findings, actions taken, and business impact. • Ensure evidence is collected, preserved, and documented appropriately. • Participate in post-incident reviews and lessons-learned sessions. Collaboration • Coordinate with IT Operations, Service Desk, Infrastructure, Network, and Cloud teams during investigations. • Communicate incident status to stakeholders and management. • Support major incident response activities and virtual war room operations during significant security events. Continuous Improvement • Contribute to development of SOC playbooks and response procedures. • Recommend improvements to detection rules, monitoring coverage, and response workflows. • Assist in threat hunting and security control validation activities. • Stay current with emerging threats, vulnerabilities, and industry best practices. Required Qualifications Education • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or equivalent experience. Experience • 2–5+ years of cybersecurity, SOC, incident response, or security operations experience. • Experience investigating security incidents in enterprise environments. • Familiarity with Windows, Linux, cloud platforms, and enterprise networking. Technical Skills • SIEM technologies • EDR/XDR platforms (Taegis , Microsoft Defender, CrowdStrike, SentinelOne, etc.) • Email security technologies • Identity platforms such as Active Directory and Entra ID
#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-
📌 SeniorAdministrator - Security Analysis, SIEM (India)
🏢 HCLTech
📍 India