HamburgerMenu
hirist

Job Description

Position Summary :

- Manage, monitor, and optimize global (GSOC) and local SOC environments.

- Protect enterprise data using advanced DLP strategies.

- Detect, analyze, and mitigate cyber threats across endpoints, proxies, and cloud infrastructure using SIEM, EDR, and automation tools.

Key Responsibilities :

SOC Operations & Incident Response :

- Triaging alerts : Monitor global and local SOC environments for real-time security events.

- Incident investigation : Execute standard Incident Playbooks to contain and neutralize threats.

- Forensic analysis : Conduct root cause analysis on network and endpoint security incidents.

- Threat hunting : Search logs proactively to identify undetected malicious activities.

SIEM Management & Engineering (ArcSight) :

- Platform administration : Manage and configure ArcSight SIEM Manager.

- Log parsing : Develop and maintain custom ArcSight Parsers for unique log sources.

- Rule optimization : Fine-tune SIEM use cases to reduce false positive alerts.

- Data correlation : Create correlation rules to detect complex attack patterns.

Data Loss Prevention (DLP) Strategy :

- Policy engineering : Design, deploy, and maintain corporate DLP policies across the enterprise.

- Tool management : Configure and manage Symantec DLP tools and technologies.

- Incident mitigation : Monitor, detect, and respond to unauthorized data transfers.

- Access governance : Implement data encryption practices to safeguard sensitive information.

Endpoint & Infrastructure Security :

- EDR management : Deploy and maintain Endpoint Detection and Response (EDR) solutions.

- Vulnerability scanning : Run network and system vulnerability assessments using Nessus.

- Endpoint control : Use Tanium for real-time asset discovery and endpoint management.

- Access controls : Manage secure web gateways (Proxies) and Mobile Device Management (MDM).

Automation & Orchestration :

- Playbook development : Build automated workflows within the SOAR platform.

- Process optimization : Streamline response times by automating repetitive analyst tasks.

- Tool integration : Connect SIEM, EDR, and DLP tools into the SOAR ecosystem.

Required Technical Skills :

- SIEM : ArcSight SIEM Manager, ArcSight Parser development.

- DLP : Symantec DLP Tool, policy creation, data classification.

- Automation : Security Orchestration, Automation, and Response (SOAR) playbooks.

- Vulnerability & Endpoint : Nessus, Tanium, EDR platforms.

- Network & Mobility : Secure Web Proxies, Mobile Device Management (MDM).

- Core Security : Cryptography/Encryption standards, threat hunting methodologies, digital forensics.

Preferred Qualifications :

- Experience working in a hybrid GSOC / Local SOC architecture.

- Industry certifications : CISSP, CEH, GCIH, or platform-specific certifications (ArcSight, Symantec, Tanium).

Work Environment :

- This position may involve working in an office setting or remotely, depending on company policies and flexibility in hours may be required to meet team needs.

Additional Information :

- Shift : General. Five days working!

- Head office & Interview location : Aviva India (HO) 401A, 4th Floor, Dlf Cyber Park, Phase II, Block A, Sector 20, Gurugram, Haryana 122002.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...