What You'll Do
- Monitor, triage, investigate, and respond to suspicious activity across all company assets.
- Perform log analysis and analyse datasets to support alert and response activities.
- Provide data driven insights to improve cybersecurity operations.
- Create & maintain detection use cases & implement improvements.
- Interface with other teams as required.
- Perform root cause analysis of security issues.
- Use a combination of manual and automated tools to proactively analyse various data.
- Help stakeholders to determine the best course of action to remedy the problem
- Work effectively with team members and leadership by communicating cybersecurity trends and sharing ideas and knowledge in a constructive and positive manner;
- Actively participate in our goal to continuously improve the way we work; identify improvement areas on our technology, process and techniques to enhance our detection and response capabilities.
- Ensure the ongoing core objectives of the CSIRT are accomplished and measurable.
- Be a part of our Security on-call rota
What you’ll need
- Minimum 3+ years working in security practices (CSIRT/SOC experience preferred);
- Demonstrable experience of the incident response lifecycle at both technical and procedural level;
- Demonstrable experience performing incident response across different operating systems
- Ability to quickly solve problems using scripting and automation;
- Solid understanding of IT fundamentals across networking, system, and application layers;
- Strong understanding of Cloud infrastructure & experience of incident response in cloud environments.
- Proven ability to prioritize incoming escalations and requests appropriately using clear communications;
- Excellent interpersonal and communication skills in order to share knowledge with peers and to communicate effectively with different stakeholders;
- Strong knowledge of Endpoint Detection and Response (EDR) tools for incident analysis;
- Expert knowledge of Secu
📌 Senior Security Analyst (Pune)
🏢 Tomtom
📍 Pune