Source description
About the role
Role & responsibilities Investigate and respond to alerts escalated by SOC team, conducting in-depth analysis before closure. Utilize SentinelOne EDR, Splunk, QRadar, and ArcSight for advanced threat validation and investigation. Apply MITRE ATT&CK framework to classify threats and recognize adversary techniques. Collaborate with cross-functional teams to enhance detection rules and response procedures.Develop detailed RCA reports and contribute to the creation of incident response playbooks. Monitor emerging threats and recommend proactive defensive measures. Work with DLP solutions like Forcepoint DLP to detect and prevent data exfiltration. Analyzed alert patterns during incident investigations and collaborated with SOC and engineering teams to suggest fine-tuning of detection logic and rule parameters. Hands-on Experience with SIEM tools FortiSIEM and SECEON including creating and fine tuning rules. Hands-on Experience with XDR tools SOPHOS Central and s1 with Onboarding End Devices Incident Response: Strong expertise in triage, containment, remediation, and post-incident documentation. Threat Hunting: Skilled in hypothesis-driven threat hunting to detect hidden adversaries using behavioral analysis and IOCs Preferred candidate profile Proficient in security monitoring, log analysis, incident detection and response, vulnerability assessment, and proactive threat hunting. email : priti.bhasin@agilityhrms.com 9811063994 .
More at Agility Human Resource Management Services