Security Analyst

1491

Applications

Bangalore
Full-Time
Senior: 7 to 10 years
5L - 17L (Per Year)
Posted on Sep 22 2023

About the Job

Skills

Splunk
qradar
Crowdstrike
sentinel
trend micro
MITRE Frameworks

Your Role and Key Responsibilities:

 

The security delivery support clients in managing their Security Operations and protecting their environments to mitigate security risks (e.g., insider and external threats, intentional and accidental). Position is for an experienced security professional with demonstrated experience within Security Operations, Threat Detection & Response, Security Intelligence, CSM (Continuous Security Monitoring) and NSM (Network Security Monitoring) within the SOC operations environment.

 

  • Work in a 24/7 Global SOC Team that operates in three shifts (6:00 – 14:00, 14:00 – 22:00, 22:0 – 6:00)
  • Conduct preliminary incident triage according to the Security Incident Management Triage Matrix and set the priority, provide analysis, determine, track remediation, and escalate as appropriate.
  • Utilize the intrusion detection, security scanning, security log collection, content filtering, and other security-related systems to perform triage and investigation and incident response
  • Provide support for security incidents coordination with SOAR platform, providing recommendations for next steps and/or containment activities, by using different communication means.
  • Ensure the SOC team documentation is up to date, including investigation Playbooks and Standard Operating Procedures as well incidents have current notes related to investigation steps which were performed.
  • Cooperation with other Security Analysts and different teams, including Threat Hunting, Threat Intelligence, Red Team, Perimeter Protection in order to improve the SOC monitoring and defense capabilities.
  • Categorization and prioritization of security incidents
  • Looking for the correlation between various security events

 

 

 

Required Technical and Professional Expertise

 

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or other related fields, from an accredited university. Equivalent professional experience can be used in lieu of a degree.

·       0-2 years of security analyst experience, preferably in a managed services environment.

·       Basic experience with operation of commonly used information security solutions (with focus on Splunk, QRadar, Crowdstrike, Sentinel, TrendMicro)

·       Base technology knowledge of Windows, Active Directory, Linux, SIEM Solutions, Antivirus software, Proxy

·       Strong knowledge of current security threats, techniques, and landscape, and a dedicated and self-driven desire to research and learn more about the information security landscape.

·       Review and triage experience with endpoint detection and response tools

·       Experience and knowledge related to the configuration and maintenance of security monitoring and reporting platforms.

·       Strong analytical skills, decision making, being able to work under time pressure, cooperating with other people and using the escalation processes when necessary.

·       Experience in technical Team coordination/management would be a plus.

·       English: Fluent

·       Strong critical thinking and analytical skills and ability to think “out of the box” required.

·       Must be able to work independently or with a team, under minimum supervision.

 

 

Preferred Technical and Professional Experience

·       MBA or master’s degree

·       A minimum of 5 years hands on experience with one or more of the following areas:

o  Operation and Implementation of SIEM solutions including:

§ QRadar or Splunk and Microsoft Sentinel.

o  Operation and Implementation of Security Automation solutions including:

§ Thorough knowledge of SOAR (Security Orchestration Automation & Response) technologies.

o  Desing and Implementation of Monitoring strategy including:

§ Thorough knowledge on defining data sources monitoring based on clients’ business  

§ Thorough knowledge on MITRE Frameworks (ATT&CK, D3FEND)

§ Familiar with Cyber Kill Chain

o  Desing and Implementation of Configuration Governance solutions including:

§ Thorough knowledge on how to operationalize ongoing security configuration governance service using SOC standard methodologies, metrics, KPIs, KRIs, Operational Procedures.

  • Cyber Network Operations/Penetration Test Methodologies and tools like Metasploit, Kali Linux, Cobalt Strike etc.,

 

 

Required Education

Bachelor's Degree

 

Preferred Education

Master’s Degree

 

 

 

About the company

Maintec Technologies Private Limited,Banagalore is an information technology and services company based out of At:Saroli,Post:Surute,Tal:Chandgad,Dist:Kolhapur,Pin-416507, Bangalore, Karnataka, India.

Industry

IT Services and IT Consul...

Company Size

51-200 Employees

Headquarter

Hyderabad

Other open jobs from Maintec Technologies Private Limited,Banagalore