RemoteFull timeMid levelPosted today
Apply with JobAssistAbout the role
Role & responsibilities
- 1-5years of experience - SOC operations, incident response, threat monitoring, or cybersecurity investigations.
- Should be working in SOC, SIEM technologies (LogRhythm, Splunk, Sentinel, Chronicle)
- EDR/XDR solutions (CrowdStrike, Cortex XDR, Microsoft Defender)
- Review and triage information security alerts worked by L1, provide analysis, determine and track remediation, and escalate as appropriate.
- Desirable to have experience of SOC Monitoring and tirage using SIEM technologies (LogRhythm, Splunk, Sentinel, Chronicle)
- Knowledge on XDR can be an added advantage
- Knowledge of security concepts such as cyber-attacks and techniques, threat vectors, risk management, incident management etc.
- Fundamental understanding of network traffic analysis including TCP/IP, routing, switching, protocols, etc.
- Reviews the most recent SIEM alerts to see their relevance and urgency. Carries out triage to ensure that a genuine security incident is occurring. Oversees and configures security monitoring tools.
- Strong understanding of Recorded Future Fusion, Brand protection cloud side..
- Inform L4 team of proactive and reactive actions to minimize false positives.
- Maintain, manage, improve and update security incident process and protocol documentation (Run Book).
- Strong understanding of Windows event log analysis.
- Acts as Security Incident Handler for high-impact cyber security incidents and advanced attacks in accordance with Cyber Kill Chain methodology and incident response process.
- Conducts malware analysis and identification of Indicators of Compromise (IOCs) to evaluate incident scope and associated impact.
- Enhances workflow and processes driving incident response and mitigation efforts.
- Practical understanding of exploits, vulnerabilities, computer network intrusions, adversary tactics, exfiltration techniques and common knowledge.
- Demonstrate proficiency in the Incident Response Process as well as the performance of threat hunting and SOC operations.
- Log analysis across disparate log sources, prioritize and differentiate between potential intrusion attempts and false alarms.
- Sound understanding of different attack frameworks like Kill Chain & MITRE & ability to utilize them for incident response & reporting.
- Bachelors orMaster’s degree in Computer Science, Information Security, or related field.
- Preferably hold at least one of the following certifications: CompTIA Security+ / CEH / ECSA /Relevant OEM certification for SIEM or security monitoring tools
- Professional is required to work from office
- Job location : Hyderabad, Mumbai
Millions of jobs, with real people getting hired every day
20,000+
New jobs added daily7,000,000+
Verified job listings500,000+
Tailored applications submittedFAQ
Questions, answered
Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.
Yes. This role at Deloitte Shared Services India was screened before publishing – we confirmed the employer before listing it.
The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.
This position can be done from anywhere, with no in-office requirement.
Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.
