This role involves Sentinel SIEM administration and operation management within a 24x7 Security Operations Centre (SOC). It requires in-depth knowledge of SIEM/SOAR/EDR tools, cloud security, incident response, and security monitoring across on-premises and cloud environments.
Responsibilities
- Sentinel SIEM administration and operation management
- Custom/unsupported devices integration with Sentinel SIEM and use cases creation
- Content creation on SIEM to cover all stages of the MITRE framework
- Design, develop, monitor, and adhere to various SLAs/KPIs/KRIs applicable to the Security Operations Centre
- Creation of customized reports and dashboards for presentation to various stakeholders
- Identify and address technical or operational risks
- SIEM and other security platform performance and capacity management
- Technical depth in one or more specialties including: Malware analysis, Host analysis and Digital forensics
- Strong understanding of Security Operations and Incident Response process and practices
- Experience performing security monitoring, response capabilities, log analysis and use of forensic tools
- Strong understanding of operating systems including Windows, Linux and OSX
- Experience with SIEM, SOAR, EDR, Network, AWS, and Azure security tools
- Experience with IR and forensic investigations within cloud environments such as AWS and Azure
- Experience with one or more scripting languages (PowerShell, Python, Bash, etc.)
- Excellent critical thinking and analytical skills, organizational skills, and ability to work as part of a team
- Excellent verbal and written communication skills
- Should be comfortable to be part of 24x7 SOC services
- Experience 5-10 years in SOC
Qualifications
- Bachelors degree relevant to Information Technology, Computer Science/Engineering (or equivalent)
- Advanced interpersonal skills to effectively promote ideas and collaboration at various levels of the organization
- One or more security-related certifications from SANS (e.g., GCIH, GCFE, GCFA) or AWS/Azure Cloud security certifications or equivalent
Locations
Ahmedabad, Gujarat, India
- Job Function: IT Software : Software Products & Services