L3-SOC ANALYST

ALTEN India

Bengaluru

On-site

INR 1,000,000 - 1,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading IT consultancy in Bengaluru is seeking a Level 3 Cybersecurity Analyst to oversee forensic investigations and cybersecurity measures. The role involves conducting forensic analysis on various systems, developing standard procedures within the Security Operations Center, and utilizing advanced forensic tools to ensure the integrity of computer-related evidence. Candidates should possess 5-8 years of experience and advanced knowledge in cybersecurity practices. This opportunity offers a dynamic environment and significant responsibilities in enhancing the organization’s security posture.

Qualifications

  • 5-8 years of experience in cybersecurity and forensics.
  • Knowledge of principles and methods of investigation.
  • Familiarity with MITRE ATT&CK framework.

Responsibilities

  • Conduct forensic analysis on systems to ensure resolution for metrics.
  • Utilize forensic tools to retrieve electronic data.
  • Communicate with implementation staff on data security incidents.
  • Perform forensic analysis on logs to identify malicious activity.

Skills

Excellent time and priority management
Ability to work in an international context
Ability to analyse and synthesise
Experience of working in a dynamic environment
Autonomy and initiative
Resistant to stress
Critical Thinking
Unquenchable curiosity

Education

General knowledge in cybersecurity
Advanced knowledge of log management

Tools

SIEM Microsoft Sentinel
Forensic tools
Security tooling: Nessus, MISP, Zscaler NSS

Job description

Key Responsibilities Of The Job

Level 3 is responsible for the development and maturity of the forensic and investigations program within the organization. He performs a variety of highly technical analyses and procedures dealing with the collection, processing, preservation, analysis, and presentation of computer-related evidence.

Experience: 5‑8 years minimum

Job Location: Bengaluru

Primary Technical Responsibilities

Primarily responsible for the administration, apps & infrastructure, playbooks, Azure functions, Defender detections rules, architecture, configuration, and analytic performance. The Level 3 analyst also develops, implements, and executes standard procedures for the “front‑end” operation within the Security Operations Center. You will also communicate with the SOC manager and analysts to optimize the detection (analytics) performance to better meet the needs of the SOC.

Additional Responsibilities Include
  • Conduct forensics analysis on systems and ensure root cause and resolution for metrics, tracking and lessons learned are compiled, documented, and disseminated.
  • Use of forensic tools and investigative methods to find specific electronic data, including internet use history, processing documents, images, and other files.
  • Responsible for disseminating and reporting cyber-related activities, conducting vulnerability analyses, conducting risk management of computer systems.
  • Analyse and review escalated cases until closure, this includes investigating and recommending appropriate corrective actions for data security incidents which includes communicating with the implementation staff responsible.
  • Perform forensic analysis on logs, traffic flows, and other activities to identify malicious activity.
  • Research, develop, and keep abreast of testing tools, techniques, and process improvements in support of security event detection and incident response.
  • Reverse engineer and analyse binaries, files, and other malicious attack artifacts.
  • Establish, maintain, and ensure complete chain of custody of forensic evidence.
  • Analyst level 3 writes up technical reports detailing how the computer evidence was discovered and all the steps taken during the retrieval process.
  • The analyst also gives testimony regarding the evidence he or she collected. The analyst keeps current on new methodologies and forensic technology.
  • This expert is not only proficient in the latest forensic response and reverse engineering skills but is astute in the latest exploit methodologies.
  • Will provide significant input into the design and development of the organizations working information security systems operations and maintain strategy and methodology to comply with the organization’s cyber security standards and mission.
  • On‑call duty
Other Duties Include
  • Capacity planning (Long-term/Short-term storage logs)
  • Change management (Analytic detections/Workbooks/Playbooks/Notebooks versioning)
  • Patch management (Security tooling: Nessus, MISP, rsyslog, Zscaler NSS)
  • Tune and optimize Azure Sentinel KQL performance and event data quality to maximize Azure Sentinel and Microsoft Defender efficiency and assist with data source correlation using Azure Sentinel and Microsoft Defender. Additionally, the Level 3 is responsible to ensure all Azure Sentinel components perform as expected meeting established service level objectives for optimal system uptime.
Interfaces
  • Group IS&T department: EUSS, IT, Front & Back Office
  • Affiliates IS&T, asset owners
  • IT Project managers
  • Technical Direction & related technical teams
  • SOC team
Education / Experiences / Skills / Competencies Required
  • Framework MITRE ATT&CK
  • Attack technique/APT
  • Monitoring, research, analysis, and response to alerts
  • Creation and implementation of use cases
  • SIEM Microsoft Sentinel
  • Principles and methods of investigation (Chain of custody, ...)
  • General knowledge in cybersecurity (vulnerabilities, cryptography, state of the art and best practices, ...)
  • Advanced knowledge of log management and analysis of all types (syslog, windows, applications, ...)
Core Skills
  • Excellent time and priority management.
  • Ability to work in an international context.
  • Ability to analyse and synthesise.
  • Experience of working in a dynamic environment and ability to multi-task.
  • Autonomy and initiative (ability to seek, find and implement a solution).
  • Resistant to stress.
  • Critical Thinking.
  • Unquenchable curiosity.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Technical Specialist - Cyber Security L3
Technical Specialist - Cyber Security L3

Lenovo • Bengaluru

On-site
INR 1,400,000 - 2,100,000
L3 SOC Analyst
L3 SOC Analyst

UST • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Sr. SOC Engineer (L3)
Sr. SOC Engineer (L3)

PeopleStrong • Chennai District

On-site
INR 1,800,000 - 2,600,000
SOC Analyst
SOC Analyst

Resillion • Bengaluru

Hybrid
INR 600,000 - 900,000
L2 SOC Analyst
L2 SOC Analyst

UST • Thiruvananthapuram

Hybrid
INR 600,000 - 900,000
TECHNICAL LEAD - SOC Monitoring
TECHNICAL LEAD - SOC Monitoring

Happiest Minds Technologies • Bengaluru

Hybrid
INR 2,500,000 - 4,000,000
SOC L3 Expert
SOC L3 Expert

Maandag® Middle East • India

On-site
INR 800,000 - 1,200,000
Security Analyst - L2
Security Analyst - L2

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,200,000 - 1,600,000
SOC-Associate Director
SOC-Associate Director

SISA • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Senior SOC L3 Analyst
Senior SOC L3 Analyst

Opt IT • India

On-site
INR 1,800,000 - 3,600,000