Should have minimum 10 - 12 years of experience as a security administrator, SOC Analyst or SIEM Admin in a Security Operations Center.
- In-depth understanding of security threats, threat attack methods and the current threat environment.
- Experience in security monitoring, Incident Response (IR), security tools configuration and security remediation • Understanding of Linux and Windows operating systems and OS event logging.
- In-depth understanding of security threats, threat attack methods and the current threat environment.
- Experience in security monitoring, Incident Response (IR), security tools configuration and security remediation.
- Investigate, document, and report on information security issues and emerging threats.
- Knowledge of networking protocols, network analysis, and network/security applications • Knowledge of security methodologies and processes, and technical security solutions (firewall and intrusion detection systems) • Previous experience with SIEM tools (Microsoft Sentinel preferred) & Security Analytics tools used in monitoring the network,
including log management systems, ticketing systems(ServiceNow), and network health systems • Experience in developing production SIEM use cases.
- Ensure effective operation of SIEM content: filters, rules, expressions and other identification mechanisms of the threat and vulnerability management technologies used within the SOC • Mentor and guide L1 & L2 Security Analysts • Provides skilled data analysis within the SOC processes and to SOC customers in order to drive further security measures and risk mitigation activities.
- Should have experience in leading & managing teams for delivering the tasks & activities.
- Should be able to represent SOC, talk to customer and senior leadership.
- Experience in preparation and presentation of SOC related dashboards, reports etc..
- Strong verbal and written interpersonal communication skills • Willingness to work in 24/7 shift timings as required to support the team or at priority calls.