12 Sep
|
Promaynov Advisory Services
|
Mumbai
12 Sep
Promaynov Advisory Services
Mumbai
Responsibilities
- Responsibilities
- Incident Response &
- Digital Forensics
- Lead end-to-end incident response investigations, including triage, containment, eradication, recovery, and lessons learned.
- Perform digital forensic investigations across endpoints, servers, network devices, cloud platforms, and applications.
- Identify, collect, preserve, and analyze digital evidence, artifacts, and Indicators of Compromise (IOCs).
- Construct detailed attack timelines and perform artifact correlation to determine attack progression and root cause.
- Conduct impact assessment and provide actionable remediation recommendations for security incidents.
Threat
Hunting
- Perform proactive threat hunting activities across enterprise environments using hypothesis-based and intelligence-driven methodologies.
- Map identified threats and adversary activities to the MITRE ATT&CK; framework.
- Research threat actors, malware campaigns, emerging attack techniques, vulnerabilities, and industry trends.
- Develop hunting strategies, detection logic, and threat intelligence use cases to improve organizational detection capabilities.
- Validate potential threats through telemetry analysis across endpoints, networks, cloud platforms, and security tools.
Detection
Engineering &
- Use Case Development
- Design, develop, validate, and optimize security monitoring use cases for SIEM, EDR, NDR, and related security technologies.
- Identify telemetry and log source gaps and recommend additional monitoring controls.
- Collaborate with SOC teams to enhance detection coverage and reduce false positives.
- Develop correlation rules and analytics for emerging threats and attack techniques. Assessment &
- Advisory
- Conduct Incident Response Readiness Assessments and maturity evaluations against industry frameworks.
- Review security controls, logging architecture, forensic readiness, and monitoring capabilities. Reporting &
- Stakeholder Management
- Prepare tactical, operational, and strategic incident reports for technical and executive stakeholders.
Required Skills &
Qualifications Technical Expertise
- Hands-on experience in Security Operations (SOC), Incident Response (IR), Digital Forensics &
- Incident Response (DFIR), and Threat Hunting.
- Solid knowledge of operating systems (Windows, Linux, Unix), networking, cloud technologies, APIs, and enterprise applications.
- Deep understanding of digital evidence collection, forensic methodologies, and security telemetry analysis.
- Expertise in analyzing logs from security and infrastructure technologies, including SIEM, EDR, firewalls, proxies, identity systems, email security, and cloud platforms.
- Working knowledge of incident response frameworks such as NIST, CERT-In, SANS, and related industry standards.
- Strong understanding of MITRE ATT&CK;, Cyber Kill Chain, Diamond Model, and threat hunting methodologies.
- Knowledge of OWASP Top 10, application security principles, and common attack vectors.
- Experience in breach timeline reconstruction, attack path analysis, and evidence correlation.
- Strong analytical, investigative, and problem-solving capabilities.
- Experience conducting cybersecurity risk assessments and developing mitigation strategies. ________________________________________
Requirements
- ISO 27001
- ISO 31000
- COSO Framework
- GRC Platforms
- Vulnerability Management Frameworks
- CHFI (Computer Hacking Forensic Investigator)
📌 Incident Response & Security Analysis (Mumbai)
🏢 Promaynov Advisory Services
📍 Mumbai