TYPE:CONTRACTUAL
LOCATION:PUNE
EXP:5+ YEARS( Immediate Joiners)
Apply only if you are comfortable with contractual position or Send updated resume to
[email protected]
QUALIFICATIONS/REQUIREMENTS
****
Certifications (1 or more of the following)
Current (not future/or planned) Certification are preferable
- SANS (SysAdmin, Audit, Network, and Security) GIAC (Global Information Assurance Certification) certification in Cyber Defense, Penetration Testing, Incident Response or Forensics
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- EC-Council certification: CEH (Certified Ethical Hacker), ECSA (Certified Security Analyst), CHFI (Computer Hacking Forensic Investigator), CND (Certified Network Defender)
- Cisco Certified Network Associate (CCNA)
Technical Skills
- Data Security o Data Loss Prevention tools, (e.g., AIP (Azure Information Protection), IRM (Information Rights management))
- Endpoint o Antivirus solutions (e.g., Microsoft Defender)
o Strong Windows and Linux administration experience o Information Security tools & packet analyses tools (e.g., Cb, Wireshark)
- OT/IIoT Security o Awareness of SCADA (Supervisory Control and Data Acquisition) / IIoT (Industrial Internet of Things) technologies
- Network Security o Firewall (e.g., Pato Alto Networks)
o Internet Protocols and Services (e.g., TCP/IP, FTP (File Transfer Protocol), HTTPS, SSH (Secure Shell))
o Intrusion Detection (e.g., IDS/IPS tools)
o Network scanning tools (e.g., NMAP)
o Networking infrastructure (Cisco is preferred)
o Information Security tools & packet analyses tools (e.g., Cb, Wireshark)
- Security Event Monitoring and Analysis o Log analysis/ Windows event analysis o Security Information and Event Management (SIEM) Chronicle and Splunk are preferred
- Compliance and Audit o Fair understanding of the NIST (National Institute of Standards and Technology) CS (Cyber Security) Framework
- Vulnerability Management o Vulnerability Testing tools (e.g., Qualys, Kali)
- Scripting/Automation o Programming/Scripting tools (e.g., Python, Bash, PowerShell, YARA-L)
- Incident Response - Security Risk o Strong troubleshooting and root cause analysis skills o Cyber outbreak management and the ability to differentiate malicious activity from directed attack patterns
- Application Security o Fair understanding of the threat modeling
- Could Security o Cloud experience (e.g., Azure, GCP (Google Cloud Platform), AWS (Amazon Web Services), Yandex, G42)
- Forensics o Malware analysis and memory analysis o Network and Host forensics
- Threat Intel o Experience in analyzing threat intel feeds.
- Email security o Phishing detection tools (e.g., Proofpoint TRAP, EXPLICIT)
- Identity & Access Management o Azure Active Directory o Cloud Access Security Broker (CASB)
o Federation o Conditional Access o Zero Trust
- Project Management o Basic project management experience
- Common Technical Skills o SharePoint and PowerBI experience are an advantage o YARA-L, PowerShell or Python coding experience is an advantage
CyberSOC Analyst is a tiered position with immediate progression within the team, reporting directly to the corresponding Cyber Security Operations Center manager. The following titles and duties for each tier are highlighted below:
Lead CyberSOC Engineer
Lead CyberSOC Engineer (T3 - Tier 3) is expected to:
- Possess all skills required of a CyberSOC Engineer (T2)
- In-depth knowledge of most of the skills listed in the “Technical Skill” section
- Ability to perform basic malware reverse engineering
- Ability to perform memory analysis using tools such as Volatility or Rekall
- Leverage forensic tools such as FTK, X-Ways, SIFT as part of an investigation
- Use both internal and external threat intelligence to build threat detections and provide data enrichment
- Threat Hunting
- Evaluate tools/solutions for investigation and IR (Incident Response)
- Ability to write scripts and Automate
- Conduct security gap analysis assessments, penetration testing / red-team assessments, and vulnerability assessments to identify security vulnerabilities
- Maintain and employ a strong understanding of advanced threats, continuous vulnerability assessment, response and mitigation strategies used in cybersecurity operations
- Mentor T1 and T2 analysts
📌 Lead CyberSOC Engineer (Pune)
🏢 Orcapod Consulting Services
📍 Pune