25 Sep
|
LTM
|
Coimbatore
Role Description
Job Summary
We are seeking an experienced Cyber Security Specialist to strengthen our organization's security operations, threat management, vulnerability management, and security engineering functions. The ideal candidate will possess solid hands-on expertise in security monitoring, incident response, threat hunting, security tool administration, and enterprise security operations. This role requires proactive identification of cyber threats, efficient incident handling, and continuous improvement of security controls across enterprise environments.
Key Responsibilities
Security Monitoring &
- Incident Response
- Monitor, analyze, and investigate security s using SIEM, EDR, and XDR platforms.
- Lead end-to-end incident response activities including triage, containment, eradication, recovery, and remediation.
- Conduct root cause analysis and post-incident reviews.
- Develop and maintain incident response procedures and playbooks.
- Coordinate with internal stakeholders during security incidents and cyber crisis situations.
Threat Detection &
- Threat Hunting
- Perform proactive threat hunting using endpoint telemetry, network traffic, and security logs.
- Develop, optimize, and tune detection rules aligned with the MITRE ATT&CK; framework.
- Identify advanced threats, malicious activities, and indicators of compromise (IOCs).
- Convert threat hunting findings into actionable detection use cases and security improvements.
Vulnerability &
- Exposure Management
- Perform vulnerability assessments and manage enterprise vulnerability scanning activities.
- Assess vulnerabilities for business impact and risk severity.
- Partner with infrastructure, cloud, and application teams to ensure timely remediation.
- Validate vulnerability fixes and ensure SLA compliance.
- Track and report remediation progress to leadership.
Security Engineering &
- Hardening
- Design, implement,
and maintain enterprise security baselines.
- Harden and secure Windows, Linux, Active Directory, Microsoft 365, and cloud environments.
- Support security testing, purple team exercises, and validation assessments.
- Improve security configurations across endpoints, servers, network devices, and cloud workloads.
Security Tools &
- Platform Management
Manage And Optimize
- SIEM &
- SOAR Platforms (Microsoft Sentinel, Splunk)
- EDR/XDR Solutions (Microsoft Defender, CrowdStrike)
- Firewalls, IDS/IPS, and Web Application Firewalls (WAF)
- Cloud Security Platforms
- Vulnerability Management Tools
Governance, Risk &
- Compliance (GRC)
- Support security audits and compliance initiatives.
- Ensure adherence to frameworks such as ISO 27001, NIST CSF, PCI-DSS, and applicable regulatory standards.
- Provide evidence collection, audit support, and compliance reporting.
- Participate in risk assessments and remediation planning.
Documentation &
- Reporting
- Maintain incident response documentation, runbooks, and operational procedures.
- Develop security dashboards and metrics including MTTD and MTTR.
- Prepare executive-level reports on security events, trends, and organizational security posture.
- Present findings and recommendations to senior management.
Required Qualifications
Education
- Bachelor's degree in Computer Science, Information Security, Cyber Security, Information Technology, or related discipline.
- Master's degree is preferred.
Experience
- 7-10 years of hands-on experience in Cyber Security, Security Operations Center (SOC), Incident Response, or Threat Management roles.
- Proven experience managing enterprise-scale security operations and incident response activities.
Technical Skills
Mandatory Skills
- EMC Networker
- SIEM Platforms (Microsoft Sentinel, Splunk)
- EDR/XDR Solutions (Microsoft Defender, CrowdStrike)
- Firewalls, IDS/IPS, and Security Monitoring Tools
- Vulnerability Management Platforms
- Windows and Linux Security Administration
- Active Directory Security
- Cloud Security Concepts (Azure, AWS, or GCP)
- Network Security and Security Operations
Framework Knowledge
- MITRE ATT&CK;
- NIST Cyber Security Framework (CSF)
- ISO 27001
- PCI-DSS
Preferred Skills
- Microsoft Defender for Office 365
- Email Security Solutions
- Data Loss Prevention (DLP)
- Imperva Database Activity Monitoring (DAM)
- Security Automation and Detection Engineering
Scripting &
- Automation
- PowerShell
- Python
- Kusto Query Language (KQL)
Preferred Certifications
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CISA (Certified Information Systems Auditor)
- GCIA (GIAC Certified Intrusion Analyst)
- GCIH (GIAC Certified Incident Handler)
- GCED (GIAC Certified Enterprise Defender)
- Microsoft SC-200
- Microsoft AZ-500
- CompTIA Security+
- CompTIA CySA+
Key Competencies
- Incident Response &
- Crisis Management
- Security Operations Center (SOC) Management
- Threat Hunting &
- Threat Intelligence
- Detection Engineering
- Risk Assessment &
- Mitigation
- Vulnerability Management
- Security Architecture &
- Hardening
- Analytical Thinking &
- Problem Solving
- Stakeholder Management
- Technical Documentation &
- Reporting
- Leadership and Team Collaboration
📌 Cyber Security (Coimbatore)
🏢 LTM
📍 Coimbatore