27 Aug
|
Infosys
|
Bhubaneswar
27 Aug
Infosys
Bhubaneswar
:
- Cisco Firewall JD
- Strong expertise in
- Cisco ASA 5500 5500 X series
- Cisco Firepower Threat Defense FTD
- Cisco FMC Firepower Management Center
- Hands on experience with
- NAT Static Dynamic PAT
- ACLs and security zones
- TCP IP routing BGP OSPF basics switching
- Deep understanding of
- Firewall policies and rule lifecycle
- VPN technologies IPsec SSL VPN
- Experience with troubleshooting tools packet capture logs debugs
- Familiarity with Snort IPS URL filtering malware protection
- Experience with SIEM tools Splunk QRadar Sentinel is a plus
- Knowledge of networking concepts and protocols
- - Preferred Skills
- Cisco certifications like
- o CCNA CCNP Security
- o Cisco Firepower certifications
- Experience in cloud security Azure AWS firewall integration
- Basic scripting Python Ansible for automation
- Understanding of compliance frameworks ISO 27001 NIST etc
- - Infra VM JD
- Web Mobile API Network Cloud VAPT
- OWASP Top 10 SANS 25 secure SDLC
- Tools Burp Suite Nmap Nessus Metasploit OWASP ZAP Frida Objection
- Security reporting risk ratings remediation guidance
- Exposure to SIEM tools and basic AWS security
Key Responsibilities:
- SOC
- At least experience in Information Security operations management with hand on experience in large security operations center using IBM QRadar Splunk ArcSight or similar SIEM tool
- Manage network endpoints and forensics initiatives malware triage and cyber security incident response
- Managing Cyber Security Services engagements and engagement teams
- Recognizing common attacker tools tactics and procedures
- Providing oversight for on site examinations and collections and technology advisory services to enhance forensic client engagements
- Researching and developing recent digital forensics scripts tools and methodologies
- Assessing and troubleshooting a variety of technical issues and support a cyber response lab on our clients SIEM tool and UEBA platform
- Assist in conducting peer reviews and providing quality assurance reviews for junior personnel and will support the mentoring of junior incident
- managers and provide guidance to others on incident management prioritization triage and report writing in support of onsite engagements
- Guiding the team to Monitor identify and investigate the security alerts and perform incident response activities related to cybersecurity incidents
- Creates new trouble tickets for alerts that signal an incident and require Tier 2 Incident Response review
- Respond to cybersecurity incidents conduct threat analysis as directed and address detected incidents for resolution
- Should be able do multitasking to coordinate incident with Sr analyst and escalation manager
- Recommend enhancements to SOC security process Operations efficiencies
- Create Incident response IR plan IR play books manage all incidents and crisis situations
- Log Analysis handle resolve security incidents
- Collaborate with respective tracks technical team for remediation of the incident
- Periodical review of incident response plan and procedures
- Recommend and document specific countermeasures and mitigating controls
- Develop comprehensive and accurate reports and presentations for both technical and executive audiences
- Preferred Skills
- Strong knowledge of cyber attacks and techniques Cyber Kill chain incident management best practices
- A high level understanding of multi tiered applications and various network and security devices protocols
- Knowledge of various operating system flavors including but not limited to Windows Linux Unix
- Proficient in preparation of reports and documentation
Preferred Skills:
Application Security,Application Security->Burpsuite,Application Security->Devsecops,Application Security->Nessus,Application Security->Wireshark,AWS DevOps,Blockchain Security,Cloud Security,Cloud Security->AWS Security,Cloud Security->Azure Security,Data Security->Data Classification,Data Security->Data Encryption,Data Security->IBM Guardium,Data Security->Public Key Infrastructure(PKI),Devops->Google Cloud Ptatform (GCP),GRC,GRC->Risk Assessment,GRC->RSA Archer(e-GRC),IDAM->CA Siteminder(CA Identity Suite),IDAM->Cyberark,IDAM->IBM Security Identity manager(ISIM),IDAM->Okta,IDAM->Oracle Access Manager(OAM),IDAM->Oracle Identity Manager(OIM),IDAM->Ping/Federate,IDAM->Sailpoint,Infrastructure Security->Antivirus,Infrastructure Security->Email Security,Infrastructure Security->Malware Analysis,Infrastructure Security->Symantec Endpoint(SEP),Network Security,Network Security->Firewalls->Checkpoint,Network Security->Firewalls->Juniper-Firewalls,Network Security->Firewalls->Palo Alto,Network Security->Firewalls->Web Application Firewall(WAF),Network Security->Load Balancer->F5,Network Security->Proxy->Blue Coat,OT Security,OT Security->OT Security,Security Incident and Event Management(SIEM)->Arcsight,Security Incident and Event Management(SIEM)->Logrythm,Security Incident and Event Management(SIEM)->QRadar,Security Incident and Event Management(SIEM)->RSA Envision,Security testing->Cloud Security,SOC,SOC->Breach Response,SOC->Security Monitoring,SOC->Security Operations Center(SOC/SIEM),Tools->Service Now->ServiceNow-Security,Tools->Splunk,Vulnerability Management
📌 Cyber Sec_Firewall_SOC/SIEM_VAPT Experts (Bhubaneswar)
🏢 Infosys
📍 Bhubaneswar