04 Sep
|
Soffit Infrastructure Services (P
|
Gurugram
04 Sep
Soffit Infrastructure Services (P
Gurugram
Job Summary
We are looking for a proactive and technically skilled Cyber Security Analyst (L1/L1.5) with hands-on exposure to Data Loss Prevention (DLP), Endpoint Detection & Response (EDR)/Antivirus (AV), and Network Access Control (NAC) technologies. The candidate will be responsible for monitoring security alerts, performing initial investigations, handling endpoint and policy-related incidents, and supporting day-to-day security operations.
The role requires positive analytical skills, understanding of cybersecurity fundamentals, and the ability to troubleshoot security incidents with minimal supervision.
Key Responsibilities
EDR / Antivirus Operations
Monitor EDR/AV console for malware, suspicious activities, IOC detections, and endpoint threats.
Perform basic threat investigation and endpoint analysis.
Isolate/quarantine endpoints when required based on standard procedures.
Validate malware alerts, suspicious files, and endpoint behavior.
Assist in IOC blocking, endpoint remediation, and policy management.
Ensure endpoint agent health and AV signature updates across systems.
DLP Operations
Monitor and analyze DLP alerts/incidents related to email, endpoint, web, USB, and cloud channels.
Perform initial triage and validation of DLP incidents.
Investigate policy violations and escalate genuine incidents as per SOP.
Assist in DLP policy tuning, whitelisting, and false-positive reduction.
Coordinate with users/business teams for incident validation and closure.
Maintain incident documentation and reporting.
Required Skills
Technical Skills
Basic understanding of:
DLP concepts and incident handling
EDR/XDR and Antivirus technologies
Windows OS, Active Directory, networking fundamentals
TCP/IP, DNS, DHCP, VPN, proxy basics
Hands-on experience with any security tools such as:
DLP: Forcepoint, Trellix DLP etc.
EDR/AV: Trellix, CrowdStrike, Defender, SentinelOne, Cortex XDR, etc.
Understanding of security incidents, malware behavior, and phishing analysis.
Basic knowledge of SIEM tools and log analysis is preferred.
Soft Skills
Positive communication and troubleshooting skills.
Ability to work in rotational shifts.
Solid analytical and problem-solving abilities.
Ability to handle multiple incidents/tasks simultaneously.
📌 Mss Analyst Edr/dlp Gurugram
🏢 Soffit Infrastructure Services (P
📍 Gurugram