We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled, inclusive culture and talent experience and our ability to be compelling to our clients. You’ll find an environment that inspires and empowers you to thrive both personally and professionally.
There’s no one like you and that’s why there’s nowhere like RSM.
We are seeking individuals with both broad and deep managed security services experience and skills to join our team and help run the ongoing security operations for RSM clients in a variety of industries and geographic locations. Successful candidates will have solid working knowledge in software integrations, working with APIs, SIEM experience, automation and orchestration software and trends, and the working knowledge to pull the whole software suite together.
At RSM, security L3 analysts work with large and small companies in variety of industries. They develop strong working relationships with their peers within the security operations center (SOC) while learning their clients’ businesses and challenges facing their organizations. Security engineers work as part of a broader team support of multiple clients.
Working in a mutually respectful team workplace helps our security teams perform at their best and integrate their career with their personal life. RSM’s security L3 analysts are responsible for advanced investigations, assist clients in incident investigations, assisting security engineers with maintaining SIEM rules, SIEM decoders, SIEM dashboards, reports, and software integrations. You will have the opportunity to:
- Use security operations center (SOC) monitoring devices (SIEM, IDS, DLP) to review and analyze pre-defined events indicative of incidents
- Understanding, identifying and researching indicators of compromise (IOCs)
- Uploading packets and evaluating source/destination activity and payloads
- Assisting in recommendations for content to detect incidents, including IOCs for blocking and detection
- Responsible for participating in threat actor based investigations, creating new detection methodologies, and provided expert support to incident response and monitoring functions
- Lead response and investigation efforts into advanced/targeted attacks.
- Hunt for and identify threat actor groups and their techniques, tools and processes.
- Provide expert analytic investigative support of large scale and complex security incidents.
- Perform root cause analysis of security incidents for further enhancement and continuous improvement.
- Provide forensic analysis of network packet captures, DNS, proxy, Netflow, malware, host-based security and application logs, as well as logs from various types of security sensors
- Work closely with security analyst to improve detection and alerting mechanisms
- Develop and document policies and procedures
- Write integrations between multiple software suites
- Work in cross functional teams
- Gain experience maintaining multi-tenant environments
- Assist in maintaining code repositories
Basic qualifications include
- Minimum B.A. or B.S. degree or equivalent from an accredited university by the time employment commences or prior relevant military / law enforcement experience
- Computer science, information technology, information systems management, or other similar degrees preferably with a focus on information security
- Previous SIEM experience
- Previous SOC experience
- Working Knowledge of at least one programming language
- Must have a naturally curious mindset and approach
- Knowledge of operating systems including Linux/Unix and Windows
- Security incident and event management (SIEM) tools such as StellarCyber, LogRhythm, Devo, ELK stack, etc.
- Working knowledge of security architectures, devices and threat intelligence consumption and management
- Be able to convert intelligence into actionable mitigation and technical control recommendations and SIEM detection rules
- Knowledge of the underlying logic that security alerts are built upon and apply them when analyzing raw logs and creating new dashboards and alerts
- Time management and multitasking skills with a high level of attention to detail
- Knowledge of common cloud platforms – Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform, Oracle Cloud Infrastructure
- Containers (Kubernetes, Docker)
and security leading practices
Beneficial, but not required, qualifications include:
- Experience with information security compliance audit frameworks and requirements e.g. PCI, FISMA, FedRAMP, SOC, SOX, PCI, GDPR and Data Privacy
- Security orchestration and automated response (SOAR) tools such as: Shuffle SOAR, Demisto, Phantom, etc.
- Knowledge and proficiency with popular cloud security services (VPC, RDS, IAM, WAF, IDS/IPS, AS3, SQS, SNS, CloudWatch, CloudTrail, Inspector, Config, etc.)
- Vulnerability tools such as: Tenable, Qualys, Rapid7, etc.
- Threat intelligence tools such as SiloBreaker, Recorded Future and MISP
- Endpoint detection/HIDS tools such as: SentinelOne, Microsoft Defender for Endpoint, CarbonBlack, Crowdstrike, etc.
- Microsoft Office 365 logging
- Cloud access service brokers such as Netskope, ZScaler, Microsoft, Forcepoint
- C# Experience
- Python Experience
At RSM, we offer a competitive benefits and compensation package for all our people. We offer flexibility in your schedule, empowering you to balance life’s demands, while also maintaining your ability to serve clients. Learn more about our total rewards at https://rsmus.com/careers/india.html. RSM does not tolerate discrimination and/or harassment based on race; colour; creed; sincerely held religious beliefs, practices or observances; sex (including pregnancy or disabilities related to nursing); gender (including gender identity and/or gender expression); sexual orientation; HIV Status; national origin; ancestry; familial or marital status; age; physical or mental disability; citizenship; political affiliation; medical condition (including family and medical leave); domestic violence victim status; past, current or prospective service in the Indian Armed Forces; Indian Armed Forces Veterans, and Indian Armed Forces Personnel status; pre-disposing genetic characteristics or any other characteristic protected under applicable provincial employment legislation.
Accommodation for applicants with disabilities is available upon request in connection with the recruitment process and/or employment/partnership. RSM is committed to providing equal opportunity and reasonable accommodation for people with disabilities. If you require a reasonable accommodation to complete an application, interview, or otherwise participate in the recruiting process, please send us an email at
[email protected].
📌 Supervisor 1, Managed Security (Hyderabad)
🏢 RSM US
📍 Hyderabad