Role
Senior IT Security Analyst
Domain
Manufacturing/Industrial/Production/Machinery
Location
Pune
Mode
On-site (5 days working from the office)
Experience
8-13 Years
Must-Haves
- The candidate must possess hands‑on expertise across a wide range of cybersecurity tools and technologies.
- Looking for L3 resource.
- Hands‑on experience including threat hunting, threat detection, and threat intelligence.
- Strong experience with CrowdStrike, vulnerability management, and handling security incidents, phishing incidents, and high‑level incident response.
Required Skills
- Significant experience in SOC, CERT, or CSIRT environments, with expertise in SIEM administration, threat hunting, detection engineering, and incident response.
- Strong expertise in configuring, optimizing, and maintaining Microsoft security products, including Sentinel, Defender for Cloud, Endpoint, Identity, Office 365, Exchange, and Azure Active Directory.
- Proficiency in log sources onboarding in SIEM, log management, developing consolidated security dashboards and developing playbooks to support continuous monitoring.
- Proficiency in creating and simulating hypothetical threat scenarios to anticipate and combat potential attack vectors.
- In‑depth understanding and practical application of the MITRE ATT&CK framework for mapping detection rules and identifying attacker tactics, techniques, and procedures (TTPs).
- Practical knowledge of security technologies, including firewalls, IDS/IPS, SIEM, endpoint detection, anti‑malware, and vulnerability assessment tools.
- Solid understanding of networks, cloud infrastructures, operating systems (Windows, Linux), and evolving cyberattack methods.
- Experience in correlating threat intelligence feeds with detection engineering to identify and mitigate advanced threats.
- Proven ability to analyze large volumes of security logs and develop precise, high‑fidelity detection rules while reducing false positives.
- Excellent communication and collaboration skills to effectively share findings and work with cross‑functional teams.
- Passionate about proactive cybersecurity measures, with a strong desire to stay updated with merging threats and technologies.
Role & Responsibilities
- Incident Response and Collaboration: Collaborate with SOC, CERT, or CSIRT teams for effective incident monitoring and response; investigate and respond to cybersecurity incidents, including forensic analysis of attack patterns.
- SIEM Administration: Provide ongoing support for SIEM architecture, ensuring efficient log ingestion, parsing, and normalization to enhance threat visibility and detection capabilities.
- Designed and customized automated playbooks and interactive dashboards in SIEM to meet specific security monitoring and incident response requirements.
- Threat Intelligence Analysis: Gather, process, and analyze threat intelligence feeds to identify emerging threats; proactively communicate relevant threat scenarios and provide actionable insights.
- Threat Detection Development: Develop and fine‑tune advanced KQL queries and analytics rules in Microsoft Sentinel to detect sophisticated attack vectors; build and test hypothetical threat scenarios to enhance threat detection capabilities; optimize detection systems to minimize false positives and maximize precision.
- Security Tool Management: Configure, monitor, and maintain security tools such as SIEM (Microsoft Sentinel), Defender for Cloud, antivirus solutions, and consolidated security dashboards.
- Continuous Improvement: Participate in developing and implementing security concepts, hardening guidelines, and monitoring systems; perform penetration tests, vulnerability assessments, and audits to ensure robust security measures; contribute to the creation and refinement of SOC policies, processes, and procedures.