04 Sep
|
Digitide Solutions
|
Bengaluru
04 Sep
Digitide Solutions
Bengaluru
Position: Security Analyst
SOC Operations | 24x7 Shift | Noida / Bengaluru
About This Role
We are seeking a vigilant and technically proficient Security Analyst to join our Security Operations Center (SOC). This is a critical role responsible for 24x7 monitoring, detection, and response to security incidents. You will work with industry-leading security tools to identify threats, investigate security events, and provide actionable intelligence to protect our organizational assets.
Key Responsibilities
1. Monitor and analyze security events and alerts from SIEM (IBM QRadar) in real-time
2. Investigate suspected security incidents and create comprehensive incident reports
3. Correlate and analyze logs from multiple security data sources and endpoints
4. Respond to security alerts related to CrowdStrike Falcon endpoints and threat detection
5. Manage and respond to Zscaler (ZIA/ZPA) security events and policy violations
6. Review and analyze Data Loss Prevention (DLP) incidents and take appropriate action
7. Monitor attack surface using specialized tools to identify external vulnerabilities
8. Perform threat hunting and proactive threat identification
9. Escalate critical incidents to senior analysts and management appropriately
10. Maintain detailed documentation of all security events and investigations
11. Collaborate with IT and business teams to remediate identified security issues
12. Participate in security alerts, on-call support, and incident response drills
Required Qualifications
1. 2+ years of experience in Security Operations Center (SOC) or cybersecurity role
2. Proven hands-on experience with IBM QRadar SIEM platform
3. Working knowledge of SIEM solutions and log management
4. Hands-on experience with Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA)
5. Strong experience with CrowdStrike Falcon platform and all its modules
6. Experience with Data Loss Prevention (DLP) solutions and policies
7. Familiarity with attack surface assessment and management tools
8. Strong understanding of network fundamentals and protocols (TCP/IP, DNS, HTTP)
9.
Knowledge of common cyber threats, attack vectors, and attack methodologies
10. Ability to work in a 24x7 shift rotation including night shifts and weekends
Required Technical Skills
1. IBM QRadar SIEM: Correlation rules, event management, alert tuning, and custom searches
2. CrowdStrike Falcon: Endpoint Detection and Response (EDR), behavioral analysis, threat hunting
3. Zscaler Services: ZIA and ZPA configuration, security policy management, log analysis
4. DLP Tools: Policy configuration, incident investigation, and false positive management
5. Log Analysis: Interpreting security logs and events from diverse sources
6. Network Protocol Analysis: Packet analysis (Wireshark), network traffic interpretation
7. Endpoint Security: Antivirus, antimalware, host-based intrusion detection (HIDS)
8. Attack Surface Visibility: External vulnerability scanning, asset discovery platforms
9. Threat Intelligence: Utilizing threat feeds, IOCs, MITRE ATT&CK; framework
10. Windows & Linux Systems: Basic security concepts, process analysis, system hardening
11. Incident Management: Ticketing systems (ServiceNow, Jira, Manage Engine), runbooks, escalation procedures
Preferred Qualifications & Skills
1. Bachelor's degree in Computer Science, Information Security, or related field (or equivalent work experience)
2. Experience with additional SIEM platforms (Splunk, ArcSight, SumoLogic)
3. Knowledge of SOAR (Security Orchestration, Automation and Response) platforms
4. Vulnerability assessment and management tools (Qualys, Tenable, Rapid7)
5. Incident response frameworks (NIST Cybersecurity Framework, MITRE ATT&CK;)
6. Cloud security experience (AWS Security Hub, Azure Sentinel, GCP)
7. Scripting knowledge (Python, PowerShell, Bash)
for automation and analysis
8. Security certifications: CompTIA Security+, CEH
9. Experience with threat hunting and Advanced Persistent Threat (APT) analysis
10. Malware analysis and reverse engineering basics
11. Knowledge of proxy and firewall technologies
Responsibilities
1. Monitor and analyze security events and alerts from SIEM (IBM QRadar) in real-time
2. Investigate suspected security incidents and create comprehensive incident reports
3. Correlate and analyze logs from multiple security data sources and endpoints
4. Respond to security alerts related to CrowdStrike Falcon endpoints and threat detection
5. Manage and respond to Zscaler (ZIA/ZPA) security events and policy violations
6. Review and analyze Data Loss Prevention (DLP) incidents and take appropriate action
7. Monitor attack surface using specialized tools to identify external vulnerabilities
8. Perform threat hunting and proactive threat identification
9. Escalate critical incidents to senior analysts and management appropriately
10. Maintain detailed documentation of all security events and investigations
11. Collaborate with IT and business teams to remediate identified security issues
12. Participate in security alerts, on-call support, and incident response drills
Qualifications
1. 2+ years of experience in Security Operations Center (SOC) or cybersecurity role
2. Proven hands-on experience with IBM QRadar SIEM platform
3. Working knowledge of SIEM solutions and log management
4. Hands-on experience with Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA)
5. Robust experience with CrowdStrike Falcon platform and all its modules
6. Experience with Data Loss Prevention (DLP) solutions and policies
7. Familiarity with attack surface assessment and management tools
8. Strong understanding of network fundamentals and protocols (TCP/IP, DNS, HTTP)
9. Knowledge of common cyber threats, attack vectors, and attack methodologies
10. Ability to work in a 24x7 shift rotation including night shifts and weekends
📌 Cyber Security Analyst (Bengaluru)
🏢 Digitide Solutions
📍 Bengaluru