- Should have a knowledge and understanding of TCP/ UDP.
- Should be able to understand and retrieve information from packet captures.
- Should have a sane knowledge of SIEM solution.
- Knowledge on Log parsing would be an added advantage.
- Knowledge on Advisories, IOCs, IOAs, Adversories.
- Understanding of an attack life-cycle and its phases.
- Understanding on actions to be done on receiving an advisory. A process that should be followed.
- Should keep his/her knowledge and should be on the top of current Cyber exploit cases going on, so that actions can be taken proactively to safeguard the setting.
Techno-Management Skill Set
- Should be able to prioritize tasks while processing advisories, incidents and events.
- How an incident should be tackled,
should have a first-hand expertise on deriving a solution and take incident to closure.
- Prepare dashboard and reports depicting an at-a-glance view of incidents, events, advisories and remedial actions.
- Work with the 3rd party solution provider for integration purpose.
- Prepare documentation related to process and Knowledge base for future easy-reference.
- Be a bridge between the technical and the management team and make sure updates are regularly submitted to higher management and review to the technical team.