Padmi

Consultant-SecOps Cyber Threat Management (Gurugram)

IndiaPosted 1 month ago
CybersecuritySeniorFull Time; Regular
Apply at BSR

Opens the source posting on shine.com

Source description

About the role

View original

Description The Consulting business at KPMG Global Services (KGS) is a diverse team of more than 6400 professionals. We work with KPMG Firms worldwide to transform the businesses of clients across industries through the latest technology and innovation. Our technology professionals combine deep industry knowledge with strong technical experience to navigate through complex challenges and deliver real value for our clients. Through your work, youll build a global network and unlock opportunities that you may not have thought possible with access to great support, vast resources, and an inclusive, supportive setting to help you reach your full potential. Responsibilities Core DeliveryBuild, tune, and maintain YARA-L detection rules (multi-event correlation, time windows, severity mapping, ATT&CK; tagging, entity enrichment).Design and implementation of enterprise security architecture with a focus on Google SecOps (Chronicle SIEM and SOAR), aligned to business and IT strategies.Design, configure, and maintain Chronicle across hybrid environments; ensure complete and accurate log collection via forwarders, Pub/Sub, Ingestion API, and vendor connectors.Create alerting, dashboards, and investigation workflows; leverage UDM Search, entities (user/asset/IP/domain), and investigation timelines to drive effective incident triage and response.Integrate Security Command Center (SCC) sources (Security Health Analytics, Event Threat Detection, Web Security Scanner) and findings into SecOps workflows; configure muting, notifiers, and routing.Conduct regular tool health checks, troubleshooting of ingestion pipelines and parsers, and data quality/coverage validation.Analysis & ReportingPerform security incident triage, investigation, containment, eradication, and recovery leveraging UDM Search, investigation timelines, and entity pivots (user, asset, IP, domain).Produce investigation reports, executive summaries, RCA, and measurable recommendations; map incidents and detections to MITRE ATT&CK.;Ensure security solutions and processes meet regulatory and compliance requirements; support evidence collection and audit readiness (SOPs, CMAs, playbooks).Operations & Engineering SupportOnboard and normalize data sources (Cloud Audit Logs, VPC Flow, Cloud DNS, GKE/container logs, Google Workspace audit logs, EDR/identity/network sources) with UDM field mappingEngineer and operationalize Google SOAR playbooks and cases for automated response.Standardize content-as-code practices (Git-based workflows, review/approval, promotion between environments) for rules, parsers, and playbooks.Client & Stakeholder EngagementProvide regular briefings to executives and technical teams; collaborate across global IR/SOC, architecture, and compliance stakeholders.Deliver knowledge transfer, playbook/runbook documentation, and enablement for SOC analysts and engineersExtended Responsibilities: Conduct tabletop exercises/purple-team validations to assess coverage and playbook efficacy; drive measurable improvements in MTTD/MTTR.Support sensitive data exposure assessments and CI/CD pipeline guardrails where relevant to SecOps telemetry and response. Qualifications Educational qualifications Bachelors degree in Computer Science / Cyber Security / IT or related fieldRelevant certifications (preferred): Google Professional Cloud Security Engineer; Google Security Operations/Chronicle training Work experience 5-7 years of experience in:Incident Response / SOC / Threat Hunting / SIEM Engineering / Cloud ArchitectureExperience in global client engagements (US/UK/Europe) preferred. Mandatory technical & functional skillsStrong understanding of:Enterprise security architecture and its alignment to business and IT strategies.Incident Response lifecycle and SOC workflowsMITRE ATT&CK; mapping for detections, hunts, and reporting.Hands-on experience in:SIEM tools (Google SecOps)EDR tools (Microsoft Defender, SentinelOne, CrowdStrike - exposure)Knowledge of:SIEM Engineering/YARA-L concepts, SOC/SOARSCC concepts and integration patterns into SecOps workflows.Strong:Analytical and problem-solving skillsTechnical report writing and documentation skillsCommunication and stakeholder engagement skills Preferred technical & functional skillsExposure to:Threat intelligence integration/enrichment (STIX/TAXII, MISP, VirusTotal, commercial feeds) and IOC lifecycle management.EDR/identity/network telemetryCloud Security ControlsFamiliarity with:Content-as-code, CI/CD for detections/parsers/playbooks; API-driven configuration management.Experience in:Threat hunting and hypothesis-driven analysis using Chronicle UDM Search and entity pivots. .

One address, no account. We’ll tell you when matching roles go live.

More at BSR

Related open roles

View all roles