Job Description
- Analyst would be part of 24×7 Cyber Security Operations function to perform security monitoring and incident response, data loss prevention, vulnerability management.
- Perform monitoring, research, assessment and analysis on alerts from various security tools, including IDPS tools, SIEM, Anomaly detection systems, firewalls, antivirus systems, user behavior analytics tools, endpoint inspection, and proxy devices.
- Follow pre-defined actions to investigate possible security incidents or perform incident response actions, including escalating to other support groups.
- Ensure proper functioning of systems in the Security Operations Centre.
- Enhance and Build Cyber threat detection use cases and assist in analyzing & reducing false positive.
- Support the development and enhancement of SOC incident response capabilities.
- Respond to inbound Change Requests (CRs), Service Requests (SRs), Queries for handling Incident Management.
- Execute daily ad hoc tasks or lead projects as needed.
Requirement
- Minimum 2-3 years of working experience in IT environment.
- Diploma/Degree in Information System/Information Security from a recognized institution. Strong knowledge on TCP/IP, Networking, Operating Systems and Cyber Security Concepts.
- Strong level of experience with and understanding of firewalls, Antivirus and endpoint detection.
- Good working knowledge of Linux including the ability to run command lines, editing files and scripting.
- Knowledge of commonly-accepted information security principles and practices, as well as techniques attackers would use to identify vulnerabilities, gain unauthorized access, escalate privileges and access restricted information.
- Solid understanding of threats reported by various data sources such as IDS/IPS, AV, HIDS/HIPS, WAFs, firewalls, and web proxies.
- Excellent communication skills.
- Experience in Scripting with Python, Bash or PowerShell is an advantage.
- Willing to work with 24×7 shift pattern that includes weekend work and also extend shift hours if required.
- Willingness to be on standby for maintaining 24×7 SOC shifts.
- Hold one or more tech certification (e.g. MCP, MSCE, CCNA Security, CEH, Security+, CSA )