24 Sep
|
Fastenal
|
Bengaluru
24 Sep
Fastenal
Bengaluru
Business Unit Overview
Working as Full-Time Information Security Analyst you will provide analysis for the purpose of supporting and enhancing the information security posture related to Fastenal's people, processes and technology.
Responsibilities:
The duties and responsibilities of this position include, but are not limited to:
- Performing Security Operations and Incident Response monitoring, triaging, investigating, and responding to security alerts and incidents through the full lifecycle (detection, containment, eradication, recovery, and post-incident review)
- Performing Security Operations and Incident Response across the Microsoft Sentinel and Defender XDR (Defender for Endpoint, Identity, Office 365, Cloud Apps) ecosystem including writing and optimizing KQL analytics rules
- Conducting proactive threat hunting across endpoint, identity, email, and cloud telemetry, and mapping activity according to the MITRE ATT&CK; framework
- Performing enrichment, malware/phishing triage, and threat-intelligence correlation to determine scope, impact, and appropriate response actions
- Documenting investigations and maintaining runbooks/playbooks; supporting automation (SOAR) to improve MTTD and MTTR
- Assisting the IT Governance, Risk, and Compliance (GRC) team to promote and ensure appropriate compliance with the agreed governance/risk framework
- Assisting in performing control framework assessments (PCI-DSS and ISO 27000) and internal/external audit engagements
- Assisting in risk and compliance evaluations of systems and business processes
- Collaborating with business units to provide analysis of security requirements
- Communicating with users and management on potential threats to the information security environment
- Maintaining a comprehensive understanding of PCI Data Security Standard (PCI-DSS)
- Recommending preventative, mitigating,
and compensating controls to ensure appropriate level of protection and adherence to the goals of the information security strategy
Required Position Qualifications: The following skills and qualifications are required for this position:
- Possess a degree in Information Technology, Computer Science and have at least 4 years of relevant experience in the areas of information security and Security Operations Center & Incident Response (SOC/IR)
- Proficiency writing and tuning detection/hunting queries (KQL) and familiarity with the MITRE ATT&CK; framework
- Having at least 2 years working experience with Microsoft Defender Extended Detection and Response (Endpoint, Identity, O365 & Cloud)
- Prior work experience implementing security standards and procedures
- Working knowledge of a broad range of security technologies, including NextGen Firewalls, Endpoint Protection/EDR, DLP, IDS/IPS, SIEM, Endpoint Protection/EDR, Anti-malware, and Vulnerability management
- Excellent written and oral communication skills
- Highly motivated, self-directed and customer service oriented
- Demonstrate strong organization, planning and prioritizing abilities
- Exhibit solid problem solving, deductive reasoning and decision-making skills
- Demonstrate strong math aptitude, attention to detail and sense of urgency
- Work independently as well as in a team environment
- Demonstrate our core values of ambition, innovation, integrity and teamwork
Preferred Position Qualifications:
- Possess professional IT Security Certification (Microsoft Security Operations Analyst (SC-200), CompTIA CySA+, GCIH, CEH, CCNA Security)
- Hands-on experience with Microsoft Sentinel, Proof Point, Cisco Umbrella, Cisco DUO, Microsoft Azure Cloud Security, Microsoft Purview
- Prior experience implementing security standards and procedures
- Demonstrate knowledge of computer operating systems (RedHat Linux, Microsoft Windows) and, virtualization technologies (VMware, Hyper-V)
- Demonstrate knowledge of networking topology concepts
- Previous scripting experience (Bash, PowerShell, Python, or others)
📌 Information Security Analyst (Bengaluru)
🏢 Fastenal
📍 Bengaluru