03 Sep
|
Soffit Infrastructure Services (P
|
Gurugram
03 Sep
Soffit Infrastructure Services (P
Gurugram
Job Summary
We are looking for a proactive and technically skilled Cyber Security Analyst (L1/L1.5) with hands-on exposure to Data Loss Prevention (DLP), Endpoint Detection & Response (EDR)/Antivirus (AV), and Network Access Control (NAC) technologies. The candidate will be responsible for monitoring security alerts, performing initial investigations, handling endpoint and policy-related incidents, and supporting day-to-day security operations.
The role requires good analytical skills, understanding of cybersecurity fundamentals, and the ability to troubleshoot security incidents with minimal supervision.
Key Responsibilities
EDR / Antivirus Operations
- Monitor EDR/AV console for malware, suspicious activities, IOC detections, and endpoint threats.
- Perform basic threat investigation and endpoint analysis.
- Isolate/quarantine endpoints when required based on standard procedures.
- Validate malware alerts, suspicious files, and endpoint behavior.
- Assist in IOC blocking, endpoint remediation, and policy management.
- Ensure endpoint agent health and AV signature updates across systems.
DLP Operations
- Monitor and analyze DLP alerts/incidents related to email, endpoint, web, USB, and cloud channels.
- Perform initial triage and validation of DLP incidents.
- Investigate policy violations and escalate genuine incidents as per SOP.
- Assist in DLP policy tuning, whitelisting, and false-positive reduction.
- Coordinate with users/business teams for incident validation and closure.
- Maintain incident documentation and reporting.
Required Skills
Technical Skills
- Basic understanding of:
- DLP concepts and incident handling
- EDR/XDR and Antivirus technologies
- Windows OS, Active Directory, networking fundamentals
- TCP/IP, DNS, DHCP, VPN, proxy basics
- Hands-on experience with any security tools such as:
- DLP: Forcepoint, Trellix DLP etc.
- EDR/AV: Trellix, CrowdStrike, Defender, SentinelOne, Cortex XDR, etc.
- Understanding of security incidents, malware behavior, and phishing analysis.
- Basic knowledge of SIEM tools and log analysis is preferred.
Soft Skills
- Good communication and troubleshooting skills.
- Ability to work in rotational shifts.
- Solid analytical and problem-solving abilities.
- Ability to handle multiple incidents/tasks simultaneously.
📌 MSS Analyst (EDR/DLP) (Gurugram)
🏢 Soffit Infrastructure Services (P
📍 Gurugram