22 Sep
|
Happiest Minds Technologies
|
Noida
22 Sep
Happiest Minds Technologies
Noida
Primary Responsibilities
- Act as incident lead for investigating and handling high-severity and complex security incidents end to end: direct scoping, containment, eradication and recovery, coordinate technical and business stakeholders, and own the root-cause analysis also provide details for post-incident review.
- Lead complex, multi-stage investigations across endpoint, identity, network, cloud and SaaS telemetry, including advanced malware analysis, credential-compromise and lateral-movement investigations, and adversary tradecraft reconstruction.
- Works on detection engineering lifecycle: define detection strategy aligned to MITRE ATT&CK; and the organisation's threat model, identify and recommend new detection logic across SIEM, XDR, EDR and SOAR, and measure coverage, precision and time-to-detect.
- Works on hypothesis-driven threat hunts based on threat intelligence, emerging TTPs and gaps in detection coverage; convert findings into current detections, playbooks and control recommendations.
- Lead Tier 2 SOC operations, including shift priorities, case load and escalation flow, ensuring SLAs and quality standards are consistently met.
- Create and maintain SOC playbook, runbook and knowledge-based library: define structure and standards, author content for complex scenarios, and ensure content stays current with tooling and threat changes.
- Identify, design and recommend process improvements across the SOC, measuring and reporting their impact.
- Contribute to and help implement the multi-year security operations strategy, including detection coverage roadmap, telemetry strategy,
automation targets and capability maturity.
- Translate security findings into risk-based recommendations for security engineering, IT and business stakeholders, and influence control and architecture decisions across teams.
- Mentor and develop Tier 1 and Tier 2 analysts through structured coaching, investigation walkthroughs and technical training; contribute to hiring and capability planning.
- Participate the SOC in cross-functional forums and with global security teams to ensure a cohesive, consistent approach to security operations.
- Provide seniors on-call escalation coverage for major incidents.
About You
- 8+ years in security operations, incident response, detection engineering or an equivalent blue-team role, including several years leading complex incidents end to end and acting as a technical escalation point for other analysts.
- Bachelor's degree in Information Systems, Cybersecurity or a related field, or equivalent experience.
- Advanced certifications such as GCIA, GCIH, GCFA, GCDA, GNFA, GREM, OSCP, Microsoft SC-200 or equivalent are highly regarded.
- Deep, hands-on expertise with SIEM (advanced KQL, SPL or equivalent, including detection authoring and performance tuning)
and EDR platforms (live response, forensic artefact collection, process-tree and memory analysis); experience with SOAR design and automation.
- Expert knowledge of Windows, Linux, Active Directory and Entra ID attack techniques and the telemetry needed to detect them; able to reconstruct an intrusion from raw logs without a playbook.
- Strong experience in cloud security monitoring and response across at least one major provider (AWS, Azure or GCP), including identity, control-plane and workload telemetry.
- Proficiency in Python or PowerShell for automation, data analysis and tooling integration.
- Deep working knowledge of MITRE ATT&CK;, the incident response lifecycle, malware analysis and phishing investigation, and experience mapping detection coverage against adversary TTPs.
- Track record of defining standards, processes and playbooks that others operate against, and of improving them based on evidence.
- Demonstrated ability to mentor analysts and raise the technical bar of a team.
- Sound, independent judgement under pressure; comfortable making and owning decisions during live incidents with incomplete information.
- Clear, structured technical writing, including incident reports, RCAs and briefings for senior technical and non-technical audiences.
- Strong influencing and collaboration skills; able to partner with engineering, IT and business teams locally and globally to drive change without direct authority.
Cyber Security, SOC 2, Threat hunting, AWS Cloud Security
📌 SENIOR SUPPORT ENGINEER - Cyber Security (Noida)
🏢 Happiest Minds Technologies
📍 Noida