Level II - Security Threat Engineer (Hyderabad)

Level II - Security Threat Engineer (Hyderabad)

24 Sep
|
HCA Healthcare UK
|
Hyderabad

24 Sep

HCA Healthcare UK

Hyderabad

Job Summary

The GCN 1 - serving as direct support to the HCA CDC corporate team - is a critical member of the 24/7 CDC team. They will use state of the art technologies to detect threats on our network and eradicate them as a member of our Cyber Defense Center (CDC). As a member of the CDC, they will operate along with a small team of like-minded individuals with a passion for cyber security. This role will provide Tier 1 and Tier 2 analysis and response to cyber security threats.

Threat Response

Engineers will be expected to detect malicious activity and support the business through the Incident Response process for both routine and major events. Successful candidates will have a passion for cybersecurity and be naturally curious and self-motivated to investigate and discover root causes of events while working in a fast-paced and sometimes stressful environment. Positive teamwork and communication skills are also vital. Our team operates as a close-knit group serving a noble purpose - to win the fight against evil every day.

General Responsibilities

Major Responsibilities

- Monitor security alert queue - investigate and triage events based on criticality. Work directly with HCA field resources and other members of Cyber Security to remediate threats. Use analytic techniques and critical thinking to determine if and when to escalate threats to larger Cyber Security team.
- Provide guidance to field resources on how to properly remediate a threat.
- Work closely with other CDC team members and members of Cyber Engineering teams to improve tools, techniques, and procedures for CDC operation.
- Provide feedback to detection engineering teams on alert fidelity to recommend alert tuning when needed.
- Continuously improve documentation of work products and processes.




- Participate in red/blue team exercises.
- Execute HCA's Incident Response plan as part of an incident response team. Serve as Incident Commander, Task Lead, or Scribe during incidents when needed.
- Routinely collaborate with individuals and teams from across the enterprise, both inside and outside Cyber.

Desired Experience

- Experience as a member of a Cyber Incident Response Team (CIRT) or comparable team.
- Experience executing an Incident Response plan, preferably based on recognized industry standards (e.g. NIST, SANS, etc).
- Experience in Windows Artifact Analysis and Initial Forensic Analysis (e.g. Program Execution, File/Folder opening, Account Usage, pulling memory, following proper evidence handling procedures, etc) using industry standard tools and available logs (e.g. Endpoint Detection and Response (EDR) tools).
- Experience in network forensic analysis to determine validity of detected events using available network logs collected via SEIM.
- Experience triaging cloud security threats (malicious workloads, unauthorized cloud access, virtualization based threats)
- Experience responding to CI/CD based threats (unauthorized access, data exfiltration, etc.)
- Experience in evidence collection for later DFIR (Digital Forensics Incident Response).
- Experience with an event/information analysis framework such as Analysis of Competing Hypotheses (ACH).
- Experience in performing security analysis or reporting utilizing Security Incident and Event Management (SIEM) Technologies. Preferably Splunk and SPL

Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

📌 Level II - Security Threat Engineer (Hyderabad)
🏢 HCA Healthcare UK
📍 Hyderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: level ii - security threat engineer (hyderabad) / hyderabad