08 Oct
|
Centrico
|
Chennai
Key Responsibilities
- Monitor security alerts and events through SIEM and other security monitoring platforms.
- Write and optimise SQL queries to search, correlate, and analyse security log data.
- Investigate alerts to identify suspicious behaviour, security incidents, and potential threats.
- Perform initial triage and escalate confirmed or high-risk incidents according to established procedures.
- Analyse logs from applications, databases, operating systems, network devices, and security tools.
- Identify patterns, anomalies, and indicators of compromise across multiple data sources.
- Support incident response, root-cause analysis, and evidence collection activities.
- Assist in developing and improving SIEM use cases, monitoring rules, dashboards, and reports.
- Document investigation findings, incident timelines, and recommended actions clearly.
- Stay informed about emerging cyber threats, vulnerabilities, attack techniques, and security technologies.
- Collaborate with infrastructure, application, database, and security teams to investigate and resolve security events.
Required Skills
- Strong analytical, logical reasoning, and problem-solving abilities.
- Working knowledge of SQL, including joins, filters and data analysis.
- Basic understanding of SIEM platforms and security event monitoring.
- Knowledge of common cyber threats, vulnerabilities, attack vectors, and indicators of compromise.
- Understanding of networking concepts, including TCP/IP, DNS, HTTP/HTTPS, firewalls, and common network protocols.
- Familiarity with Windows and Linux operating systems.
- Ability to interpret logs and correlate information from multiple sources.
- Good written and verbal communication skills.
- Strong attention to detail and the ability to work methodically during investigations.
- Ability to use AI-assisted tools to support security-event analysis, query development, threat investigation, and reporting.
- Awareness of AI-related cyber security risks, including data leakage, prompt injection, model misuse, and AI-generated threats.
Preferred Knowledge
- Exposure to SIEM platforms such as Microsoft Sentinel, Splunk, IBM QRadar,Arcsight or LogRhythm.
- Basic understanding of scripting languages such as Python, PowerShell, or Bash.
- Familiarity with incident response processes and security frameworks such as MITRE ATT&CK; and NIST.
- Knowledge of cloud security concepts in Azure, AWS, or Google Cloud.
- Awareness of vulnerability management, endpoint security, identity security, and data protection principles.
- Relevant certifications such as Security+, SC-200, CEH, or equivalent certifications are advantageous but not mandatory.
Educational Qualification
- Bachelor’s degree in Cyber Security, Computer Science, Information Technology, Electronics, or a related discipline.
- Candidates with relevant practical training, internships, certifications, or demonstrable cyber security projects may also be considered.
Key Personal Attributes
- Strong hunger for learning and developing recent technical skills.
- Genuine passion for cyber security and threat investigation.
- Curious mindset with an interest in understanding how systems and attacks work.
- Self-motivated, disciplined, and willing to take ownership of assigned activities.
- Ability to work independently and collaborate effectively within a team.
- Comfortable working in a continuously evolving security environment.
📌 Information security analyst (Chennai)
🏢 Centrico
📍 Chennai