06 Sep
|
Drona Cyber Solutions
|
Ahmedabad
06 Sep
Drona Cyber Solutions
Ahmedabad
Continuously monitor SIEM dashboards and alert queues for security events across on-premises, hybrid, and cloud environments.
- Perform real-time alert triage and categorize events based on severity, confidence, and business impact.
- Identify false positives and alert misfires and communicate rule tuning recommendations to SOC L2.
- Analyze correlated alerts involving multiple log sources (firewall, EDR, proxy, AD, security appliances).
- Perform first-level investigation on alerts involving suspicious IPs, malicious URLs/domains, brute-force attempts, unusual process executions, data transfers, or policy violations.
- Extract and compile relevant evidence such as event logs, Sysmon artifacts, endpoint activity, and network traces.
- Conduct IOC enrichment using Virus-Total, ANY.RUN, Hybrid Analysis, Abuse-IPDB, WHOIS, and OSINT platforms.
- Validate whether activity maps to known attacker TTPs using the MITRE ATT&CK; Matrix.
- Report observed attack patterns, indicators, and behavioural anomalies with proper justification.
- Perform containment actions approved for L1 level—account disablement, isolation requests, password resets, URL blocking, IP blocking, or alert suppression.
- Follow Incident Response playbooks and escalate incidents to SOC L2/IR team within SLA.
- Document every step taken during triage, analysis, containment, and escalation.
- Assist the L2 team during incident coordination, evidence preparation, and timeline reconstruction.
- Analyze logs from Windows, Linux, Azure AD, O365, VPN, network appliances, endpoint tools, and cloud platforms.
- Report log source connectivity failures or ingestion delays to L2 or the Engineering team.
- Maintain all SOC shift sheets, daily log books, alert trackers, and incident registers with 100% accuracy.
- Ensure explicit, structured shift handovers with detailed updates on pending alerts, incidents, and ongoing investigations.
- Prepare daily alert summary reports and client-wise incident reports.
- When needed, e
📌 SOC Engineer (Ahmedabad)
🏢 Drona Cyber Solutions
📍 Ahmedabad