- Lead and drive cross-functional delivery team, working with Program Managers, Delivery Head & Group CISO to ensure successful delivery of security operations by establishing Key Performance Indicators (KPIs).
- Provide the first-line supervision of Security Operations Center (SOC) services to ensure delivery within the agreed service levels.
- Assist and ascertain real time analysis of security events from multiple log sources and participate in providing containment recommendations.
- Drive (Major) Incident Response activities to ensure faster containment and effective eradication of threats.
- Must have sound understanding of SIEM (Microsoft Sentinel), EDR/XDR (Microsoft Defender XDR, CrowdStrike Falcon).
- Contribute to the development and improvement of security detection, Incident response process and solutions are required to support ongoing operations.
- Proactive detection, threat hunting and IOC enrichment and analysis leveraging global threat intelligence (MITRE ATT&CK;).
- Maintain Standard Operating procedures, Processes for Security Operations, perform periodic review and Updates on SOPs, Operational Documents, Troubleshooting Documents.
- Resolve the problem independently and manage the first level escalations.
- Understanding of TCP/IP stack, OSI model, Network protocols and cyber security attacks.
- Perform Root Cause Analysis and Advanced Reporting of threats and risk identified for an organization.
- Assist in capacity Planning with SIEM Engineering/Pre-Sales Team.
- Attending various audits which are initiated by various stake holders and closing audit observations.
- Plan and implement service improvement initiatives within organization.