01Key Responsibilities
- The candidate must have proven expertise in:
- Monitor SIEM tools (e.g., LogRhythm, QRadar, Splunk etc.) for security alerts. Monitoring SIEM Solution console for identifying the security events generated by the log sources integrated with SIEM tools. ~~ - Conduct in-depth analysis of security incidents. Perform threat hunting and malware analysis. ~~ - Coordinate with IT teams to contain and remediate threats. Lead deep-dive investigations and forensic analysis. ~~ - Act as escalation point for L1 and L2 analysts. Develop and implement advanced detection and response strategies. ~~ - Perform impact analysis before deployment of correlation rules. ~~ - Perform impact analysis for update and upgrade of SIEM & Advance security solutions components. ~~ - Define Mitigation suggestions for newly identified incidents. Review and approve the reports before sharing with others. ~~ - Coordinate with external stakeholders (e.g., law enforcement, vendors). ~~ - Mentor junior analysts and conduct red/blue team exercises. ~~ - Review and update the SOPs, conduct various cyber resilience scenario based exercises, conduct tabletop exercises. ~~ - Lead and manage Security Operations Centre. ~~ - To identify key contacts for incident escalation and change management activities. Ensure compliance to SLA. ~~ - Responsible for team and vendor management. ~~ - Responsible for overall use of resources and initiation of corrective action where required for Security Operations Center. ~~ - Escalate to the other IT Infra. Management teams or application maintenance teams, as necessary. ~~ - Point of contact for problem escalation and reporting. ~~
- Ideal Candidate:
- Expert-level knowledge of cybersecurity frameworks (e.g., MITRE ATT&CK;). ~~ - Hands-on experience with threat intelligence platforms and advanced analytics. ~~ - Expert knowledge on corelation rules and impact analysis. ~~ - Strong leadership, communication, and incident management skills. ~~ - Minimum 4 or more years of experience in C-SOC operations. ~~
- Certification: (*Mandatory any one of the following certifications)
- Certified Ethical Hacker (CEH). ~~ - CISSP. ~~ - GIAC Security Operations Certified (GSOC). ~~ - GCIH (GIAC Certified Incident Handler). ~~ - MITRE ATT&CK; Defender (MAD). ~~
- Compensation:
- Commensurate with experience and industry standards. ~~ .