24 Sep
|
Briskinfosec Technology And Consulting
|
Chennai
24 Sep
Briskinfosec Technology And Consulting
Chennai
Key Responsibilities
- Monitor and analyze security alerts and events using Blacklight AI SIEM.
- Perform L2 level investigation and triage of security incidents.
- Correlate events across multiple log sources to identify potential threats and attack patterns.
- Investigate suspicious activities, security alerts, and potential compromises.
- Analyze logs from firewalls, endpoints, servers, applications, network devices, and other security controls.
- Identify false positives and validate genuine security incidents.
- Perform incident enrichment using threat intelligence, IOCs, IP/domain reputation, and other relevant sources.
- Escalate confirmed or complex incidents to L3 / Incident Response teams when required.
- Create and maintain detailed incident investigation and response documentation.
- Support incident containment, remediation, and recovery activities.
- Perform root-cause analysis and provide recommendations to prevent recurrence.
- Assist in developing and tuning SIEM correlation rules, detection use cases, and alert thresholds.
- Identify gaps in existing detection mechanisms and recommend improvements.
- Prepare daily/weekly/monthly SOC reports and incident summaries.
- Maintain adherence to SOC processes, SLAs, escalation matrices, and security procedures.
- Stay updated on emerging threats, vulnerabilities, attack techniques, and MITRE ATTCK techniques.
Required Skills
Mandatory
- Hands-on experience with Blacklight AI SIEM - Mandatory
- 2-5 years of experience in a SOC / Security Operations setting.
- Strong understanding of SIEM concepts, log management, event correlation, and security monitoring.
- Experience in incident triage and investigation.
- Good knowledge of network security concepts such as TCP/IP, DNS, HTTP/HTTPS, VPN, SMTP, and common network attacks.
- Experience analyzing security logs and identifying suspicious patterns.
- Knowledge of incident response and security incident lifecycle.
- Understanding of MITRE ATTCK framework and common attack techniques.
- Good knowledge of Windows and Linux security events/logs.
- Ability to investigate and correlate multiple security events to determine the nature and severity of an incident.
Good to Have
- Experience with other SIEM platforms such as Splunk, IBM QRadar, Microsoft Sentinel, Wazuh, etc.
- Experience with EDR/XDR platforms such as CrowdStrike, Microsoft Defender, or similar tools.
- Knowledge of threat intelligence platforms and IOC investigation.
- Familiarity with vulnerability management and security tools.
- Basic scripting knowledge in Python, PowerShell, or Bash.
- Relevant certifications such as Security+, CEH, CySA+, SC-200, GCIH, or equivalent.
- Willingness to work in 24 7 rotational shifts, if required.
Key Competencies Blacklight AI SIEM | Security Monitoring | L2 Incident Response | Incident Investigation | Log Analysis | Threat Detection | SIEM Correlation | MITRE ATTCK | Threat Intelligence | IOC Analysis | Network Security | Windows Linux Security | EDR/XDR | Incident Triage
Job Overview
Location
Chennai, India
Job Type
Full-time
Category
Technology IT
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 SOC Analyst (Chennai)
🏢 Briskinfosec Technology And Consulting
📍 Chennai