19 Sep
|
HCLTech
|
Gautam Buddh Nagar
19 Sep
HCLTech
Gautam Buddh Nagar
Sr Administrator (Support & Operations)
Gautam Buddha Nagar, Uttar Pradesh
Job Summary
Monitor and analyze security events and threats as part of a 24x7x365 SOC workplace.
- Perform daily triage of alerts and tickets, leveraging threat intelligence and escalating incidents as needed.
- Act as a technical escalation point for SOC analysts and mentor junior team members.
- Lead incident response activities, conducting technical investigations and providing expert guidance.
- Conduct cyber threat research to enhance SIEM use cases and playbook development.
- Perform proactive threat hunting and investigations without predefined indicators of compromise.
- Collaborate with engineering teams to evaluate and implement new or updated security solutions.
- Support and manage security tools including EDR, WAF, and NIDS platforms.
- Automate repetitive SOC tasks to improve operational efficiency and reduce manual errors, using scripting and workflow tools.
- Troubleshoot and resolve log related issues, ensuring minimal disruption to business operations and adherence to SLAs.
- Support internal and external audits by providing evidence.
- Participate in disaster recovery drills, security assessments, and SOC-related risk mitigation activities.
- Work within ITSM frameworks to manage incidents, changes, and service requests.
Key Responsibilities
Excellent communication and interpersonal skills both written and oral.
- Client relationship management
- Ability to work hands on tools and processes.
- Willing to work 24x7 project timelines
Skill Requirements
Advanced expertise in using SIEM technologies for event investigation and threat detection.
- Strong knowledge of Windows Active Directory, Group Policies, and PowerShell scripting.
- Proficient in log analysis across Windows, Linux, Azure, O365, AWS, Google Cloud, network, and endpoint security controls.
- Familiarity with the MITRE ATT&CK; framework for understanding adversary tactics and techniques.
- Experience in malware analysis and working with Endpoint Protection and EDR solutions.
- Knowledge of content filtering technologies and their application in enterprise environments.Solid understanding of network fundamentals including OSI model, TCP/IP, DNS, HTTP, SMTP, and
packet capture/analysis.
- Hands-on experience with cloud platforms such as AWS, Google Cloud, and Microsoft Azure.
- Deep understanding of malware capabilities, attack vectors, and their potential impact.
- Skilled in threat analysis and vulnerability assessment methodologies.
- Experience with vulnerability scanning tools and technologies.
- Working knowledge of firewalls, VPN technologies, IDS/IPS, and web application firewalls.
- Familiarity with host-based intrusion detection systems.
- Proven experience in incident response and a solid understanding of IT Service Management (ITSM)
processes such as change, incident, and problem management.
Other Requirements
📌 Sr Administrator (Support & Operations) (Gautam Buddh Nagar)
🏢 HCLTech
📍 Gautam Buddh Nagar