12 Sep
|
FetchJobs.co
|
India
12 Sep
FetchJobs.co
India
About The Company
Insight Global is a leading talent and workforce solutions provider dedicated to connecting top-tier professionals with innovative organizations across various industries. With a strong commitment to excellence, diversity, and integrity, Insight Global has established itself as a trusted partner in delivering tailored staffing and consulting services. Our extensive network, industry expertise, and focus on client satisfaction enable us to help organizations achieve their strategic objectives by sourcing highly skilled talent and providing comprehensive workforce solutions.
About The Role
We are seeking a highly experienced Cybersecurity Incident Response Lead to join our dynamic team at Insight Global. In this critical role, you will be responsible for managing and leading the investigation and response efforts for major cybersecurity incidents. Your expertise will be vital in defending our organization against sophisticated cyber threats, minimizing impact, and ensuring rapid recovery.
This position requires a seasoned professional with a deep understanding of incident response methodologies, threat intelligence, and security operations. The role operates on a night shift schedule, offering an opportunity to work in a challenging environment with a focus on proactive security measures and incident management processes.
Qualifications
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field.
- Minimum of 10 years of professional experience in cybersecurity, with substantial expertise in Security Operations Center (SOC) functions and incident response.
- Proven track record of leading investigations into major cybersecurity incidents and security breaches.
- Strong knowledge of incident response frameworks, attacker tactics, techniques, and procedures (TTPs), and forensic investigation methods.
- Experience working within enterprise or global security infrastructures, demonstrating ability to operate in complex environments.
- Exceptional coordination skills to manage technical and non-technical stakeholders during high-pressure incident scenarios.
- Hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, Elastic, or LogRhythm.
- Proficiency with Endpoint Detection and Response (EDR) tools like Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black.
- Strong scripting and query language skills, including KQL, SPL, Python, PowerShell, or Bash/Shell scripting.
- Experience with API integrations and automation workflows to enhance incident response efficiency.
- Preferred certifications include GIAC GCIH, GCFA, GCED, CISSP, CSA, or Microsoft Security Operations Analyst.
- Completion of SANS Incident Response training or equivalent is highly desirable.
Responsibilities The key responsibilities of this role include:
- Lead the investigation and response of major cybersecurity incidents, including ransomware, phishing, insider threats, malware, credential compromise, and data breaches.
- Perform incident triage, analysis, containment, eradication, recovery, and post-incident activities to ensure comprehensive incident management.
- Conduct root cause and impact analysis to identify attack vectors, affected systems, and business implications.
- Analyze security alerts, logs, network traffic, endpoint telemetry, cloud activity, and threat intelligence to determine the scope of incidents.
- Utilize security tools such as SIEM, EDR, NDR, cloud security platforms, email security, and identity security solutions to investigate and respond to threats.
- Correlate data from multiple security technologies to identify malicious activity, reconstruct attack timelines,
and understand threat actor behaviors.
- Perform proactive threat hunting activities to identify indicators of compromise (IOCs) and attacker tactics, techniques, and procedures (TTPs).
- Serve as the technical lead during major incidents, coordinating response efforts across cybersecurity, infrastructure, cloud, application, legal, privacy, and compliance teams.
- Provide transparent and timely incident communications, including status updates, executive briefings, and regulatory reporting.
- Develop, maintain, and optimize incident response playbooks, runbooks, and standard operating procedures to ensure consistency and efficiency.
- Design and implement automation and SOAR workflows to streamline investigations and response processes.
- Create and enhance detection rules, use cases, and response strategies, continuously improving based on lessons learned, threat intelligence, and incident trend analysis.
Benefits Insight Global offers a comprehensive benefits package designed to support our employees' well-being and professional growth. This includes competitive salary packages, health insurance plans, retirement savings options, paid time off, and opportunities for continuous learning and development. We foster a cooperative and inclusive work environment that encourages innovation, recognition, and career advancement. Additionally, our employees have access to various wellness programs, employee assistance programs, and flexible work arrangements to promote a healthy work-life balance.
Equal Opportunity
Insight Global is an equal chance employer committed to fostering an inclusive environment for all employees and applicants. We do not discriminate based on race, color, religion, sex, national origin, age, disability, sexual orientation, gender identity, or any other protected characteristic. We believe that diversity enhances our organizational strength and are dedicated to providing equal employment opportunities to all individuals.
📌 Cyber Security Engineer (India)
🏢 FetchJobs.co
📍 India