Position Title: Sr. Analyst – SOC /n Business / Function: GRAMAX Cybertech /n Department / Sub-Department: Cyber Security /n Location: Delhi /n 1.
Key Accountabilities /n Responsibilities/duties associated with the job. Where defined, the Key Performance Indicator (KPI) used to judge performance is listed beneath the accountability. /n /n
- Continuous monitoring of security alerts and respond to the incidents as per the laid down actions of Run Book
/n
- Provide incident investigation as per Security Incident Management Process / Guidelines
/n
- Drive containment strategy during data loss or breach events
/n
- Triage and resolve advanced vector attacks such as botnets and Advanced Persistent Threats (APTs)
/n
- Perform investigations in response to escalated security alerts, gather evidence and determine RCA of the security incident
/n
- Plan for adversary eviction and incident response
- Provide inputs for forensic analysis and investigation of incidents
/n
- Carry out continuous threat collection and proactively identify threats for global clients to complement the standard SOC
/n
- Identify requirements and drive appropriate solutions
/n
- Create customized use cases as per the environment and fine-tune the security solution
/n
- Provide guidance to member analysts in the team
/n
- Create technical documentation (SOPs, run books, etc.)
/n
- Contribute to identification (hunting) and profiling of threat actors and TTPs; detect current threats and build/run custom analysis models using security event data
/n
- Ensure integration of current security infrastructure and indicators
/n
- Assist in development of the Threat Hunting service and conduct threat hunting
/n
- Execute the incident management process
/n
- Handle customer interactions and in office engagements
/n
- Align weekly/fortnightly reviews with client and Sr.
Security Delivery
Manager
/n
- Work with XDR and SIEM solutions such as QRadar, Seceon, ArcSight, Splunk, etc.
/n
- Coordinate with IT, security operations and other teams for remediation and mitigation as appropriate
/n
- Perform Root Cause Analysis (RCA) for incidents and update the knowledge document
/n
- Handle incident escalations from other analysts; project and manage incident responses and coordinate remediation with customers
/n
- Create SOPs for L1 and L2 Incident Response processes
/n
- Train L1/L2 analysts on advanced threat analysis and APT analysis using various tools
/n
- Perform in-depth malware analysis of network activity, disks and memory
/n
- Analyze threat and vulnerability alerts, determine current impact and coordinate remediation actions as necessary
/n
- Conduct detailed analysis using a variety of tools and techniques to investigate, navigate, correlate and understand security incidents
/n
- Work directly with data asset owners and business response plan owners during high-severity incidents
/n
- Provide fine-tuning recommendations to administrators based on findings during investigations or threat information reviews
/n
- Maintain knowledge of network security zones, firewall configurations and IDS policies
/n
- Maintain knowledge of systems communications from Layer 1 to Layer 7
/n
- Bring experience in Systems Administration, Middleware and Application Administration
/n
- Bring experience with Network and Network Security tools administration
/n
- Aggregate and parse log data (syslog, HTTP logs, DB logs) for investigation purposes
/n
- Use log search tools with regular expressions and natural language queries