29 Aug
|
Tata Consultancy Services
|
Chennai
29 Aug
Tata Consultancy Services
Chennai
Role & responsibilities
Security Monitoring & Incident Response
- Execute/lead initial containment, forensics scoping, and stakeholder updates; align with both best industry practice and internal IR playbooks.
- Lead investigations across Defender XDR/MDE and CrowdStrike (process trees, lateral movement, identity signals).
- Use Tanium for rapid endpoint scoping and live response actions (as per policy).
- Analyse Joe Sandbox reports (behaviour trees, network indicators, dropped files); derive IOCs/YARA candidates; coordinate containment.
- Design/maintain Cortex XSOAR playbooks (data enrichment, containment workflows, approvals, notifications); implement guardrails.
Threat Detection & Hunting
- Deep familiarity with Azure AD/Entra ID, Azure Activity/Signin logs, M365 audit logs, as well as AWS and GCP logs.
- Author and tune analytic rules in Sentinel (KQL),
Elastic (DSL/EQL/KQL/ESQL), Sigma; reduce false positives; add entity mapping and suppression logic.
- Proactive hunts using ATT&CK-aligned; hypotheses (credential theft, persistence, C2); pivot across endpoint, identity, network, and cloud logs.
- Maintain GitLab repos (branching, merge requests, CI checks for detections) and workflows for detection content (code reviews, approvals, CI quality checks).
Expertise:
- Deep knowledge of SIEM, SOAR, and EDR platforms
- Deep knowledge of threat intelligence, and incident response frameworks
- Familiarity with MITRE ATT&CK;, NIST, and ISO 27001 standards
- Ability to analyse logs, network traffic, and malware indicators
📌 SOC Analyst (Chennai)
🏢 Tata Consultancy Services
📍 Chennai