23 Sep
|
Tata Communications
|
Mumbai
23 Sep
Tata Communications
Mumbai
Responsibilities
- Responsible for 24x7 monitoring of SIEM alerts and security events, performing initial alert triage, identifying potential security incidents, and escalating confirmed or suspicious events to L2/L3 teams within defined SLAs.
- Monitor SIEM dashboards, alerts, events and security incidents on a 24x7 basis.
- Perform L1 alert triage and validate security events.
- Analyze logs from Firewall, WAF, Proxy, EDR, Windows/Linux, AD, DNS, VPN, Email Security and other security devices.
- Identify True Positive (TP) and False Positive (FP) alerts.
- Perform initial investigation of suspicious IPs, domains, URLs, hashes, users and hosts.
- Correlate events from multiple log sources to identify potential threats.
- Escalate confirmed/suspicious incidents to L2/L3 as per the defined escalation matrix.
- Create and update tickets with complete investigation details and evidence.
- Ensure alerts and incidents are handled within defined SLA/KPI timelines.
- Maintain proper shift handover and communicate all pending/high-priority incidents.
- Follow documented SOPs, playbooks and escalation procedures.
- Support daily SOC reports, incident reports and shift reports.
- Monitor SIEM health, log source connectivity and report ingestion issues to the respective teams.
- Participate in incident response, vulnerability-related investigations and security investigations as required.
- Maintain confidentiality and follow organizational security policies.
📌 Engineer - Captive Operations (Mumbai)
🏢 Tata Communications
📍 Mumbai