Padmi

Threat Detection and Monitoring Specialist

IndiaPosted 2 months ago
CybersecurityJuniorFull Time; Regular
Apply at CrimsonLogic

Opens the source posting on shine.com

Source description

About the role

View original

As a Tier1 security analyst in the 24x7 Security Operations Center, your role involves monitoring the environment for potential security threats and incidents. You will be responsible for identification, triaging, analysis, threat-hunting, incident investigation, and supporting remediation recommendations to mitigate security threats effectively. Key Responsibilities: - Operate on a 12-hour shift basis (24x7 coverage) to continuously monitor security alerts in SIEM platforms for potential security incidents. - Triage and prioritize alerts based on severity, impact, and organizational risk. - Perform initial analysis to validate alerts, determine legitimacy, and escalate confirmed or suspicious incidents as necessary. - Track and analyze suspicious network, application, and user behavior to identify anomalies and threats. - Ensure timely escalation of incidents to customers in accordance with defined SLAs, maintaining clear communication and updates throughout the incident lifecycle. - Collaborate with L2 analysts for in-depth investigation, containment, and resolution of security incidents. - Utilize ticketing systems to log, track, and manage incidents through to closure, ensuring proper documentation and audit trail. - Participate in incident response activities in alignment with the predefined Incident Response Plan and playbooks. - Adhere to Standard Operating Procedures (SOPs) for alert handling, escalation, and communication. Maintain awareness of current threats, vulnerabilities, and emerging attack techniques that may impact the organization. Qualifications Required: - Bachelor's degree in computer science, Cybersecurity, or a related field. - 0-2 years of experience in SOC, IT support, network administration, or a related field with exposure to security concepts. - Experience in monitoring and responding to security incidents. - Familiarity with security tools such as SIEM platforms, especially Azure Microsoft Sentinel or Elastic SIEM. - Robust analytical and problem-solving skills. In addition to the Key Responsibilities and Qualifications Required, you are expected to have proficiency in KQL and other query languages for threat analysis, familiarity with MITRE ATT&CK framework and its application in threat detection, strong knowledge of incident response processes and security monitoring tools, and the ability to handle high-severity incidents and make quick decisions under pressure. Please note that you will be required to work on a 12-hour shift rotation. As a Tier1 security analyst in the 24x7 Security Operations Center, your role involves monitoring the environment for potential security threats and incidents. You will be responsible for identification, triaging, analysis, threat-hunting, incident investigation, and supporting remediation recommendations to mitigate security threats effectively. Key Responsibilities: - Operate on a 12-hour shift basis (24x7 coverage) to continuously monitor security alerts in SIEM platforms for potential security incidents. - Triage and prioritize alerts based on severity, impact, and organizational risk. - Perform initial analysis to validate alerts, determine legitimacy, and escalate confirmed or suspicious incidents as necessary. - Track and analyze suspicious network, application, and user behavior to identify anomalies and threats. - Ensure timely escalation of incidents to customers in accordance with defined SLAs, maintaining clear communication and updates throughout the incident lifecycle. - Collaborate with L2 analysts for in-depth investigation, containment, and resolution of security incidents. - Utilize ticketing systems to log, track, and manage incidents through to closure, ensuring proper documentation and audit trail. - Participate in incident response activities in alignment with the predefined Incident Response Plan and playbooks. - Adhere to Standard Operating Procedures (SOPs) for alert handling, escalation, and communication. Maintain awareness of current threats, vulnerabilities, and emerging attack techniques that may impact the organization. Qualifications Required: - Bachelor's degree in computer science, Cybersecurity, or a related field. - 0-2 years of experience in SOC, IT support, network administration, or a related field with exposure to security concepts. - Experience in monitoring and responding to security incidents. - Familiarity with security tools such as SIEM platforms, especially Azure Microsoft Sentinel or Elastic SIEM. - Robust analytical and problem-solving skills. In addition to the Key Responsibilities and Qualifications Required, you are expected to have proficiency in KQL and other query languages for threat analysis, familiarity with MITRE ATT&CK framework and its application in threat detection, strong knowledge of incident response processes and security monitoring tools, and the ability to handle high-severity incidents and make quick decisions under pressure. Please note that you will be required to wo

One address, no account. We’ll tell you when matching roles go live.

More at CrimsonLogic

Related open roles

View all roles