Padmi

Asst Director - Cyber Defense

MumbaiPosted 6 months ago
CybersecurityStaff+
Apply at MyCrisil

Opens the source posting on naukri.com

Source description

About the role

View original

Role / Designation: Associate Director, Cyber Defense Job Level : 13 A Job location: Mumbai Employment type: On Roll Reporting Manager: Director, Infosec Accountabilities: 1. Implement and operate a Security Information and Event Management (SIEM) Solution (Sentinel, QRadar etc.) 2. Manage and guide the SOC team that detects, analyses, investigates, remediates, and respond s to security incidents and threats Should be able to supervise the SOC team. Provide technical guidance if needed, but most importantly, oversee adequately managing the team Surveillance Should be able to guide the team on Monitoring of event logs on networks, systems, devices, and infrastructure for unusual or suspicious activity. Threat prevention and detection including intelligence gathering to help deter potential threats and attacks. Incident analysis and investigation Forensic examination to determine the incident or threat s source and the extent to which it has infiltrated and affected business systems. Threat or attack response Coordination of an approach to effectively manage and contain the threat or incident. Recovery and remediation Retrieval of lost or stolen data and an examination of what assets have been compromised, as well as addressing vulnerabilities and adjusting security monitoring and alerting tools and procedures. 9. As the Head of SOC, should focus primarily on tools and technologies that assist security experts to monitor, analyze, investigate, and respond to security incidents, such as: a. Behavioural Monitoring ( UEBA) Assists security experts in creating a baseline when using machine learning or behaviour modelling to identify security concerns. b. Intrusion Detection System ( FW Logs analysis / WAF Log Analysis) Helps security experts detect an attack at the initial phases. c. Endpoint Detection and Response ( EDR Logs analysis & network isolation / Proxy logs study) Provides visibility and containment options. d. Log Collection and Aggregation Offers log availability and retention through a centralized repository to assist with analysis. e. Automated Malware Analysis and Sandboxing Provides understanding of malware purpose and generates indicators of compromise (IOCs). f. Disassembler and Debugging Technologies Assists SOC teams when reverse engineering and analyzing complex binaries to determine threat purpose, functionality, and capabilities. 10. Assess and review incident and compliance reports and present the same to business executives & Leadership Team Education / Experience / Other Information Bachelor degree in Engineering or Graduation in Computer Science degree or equivalent degree CISSP, CEH, OEM certifications etc will be an advantage 12-18 years overall experience in Technology and Security technologies / tools, including SIEM deployment, SOC Monitoring, Investigation, Log reviews Should have done at least 3 SIEM deployment at a technical level (not PMO level) Should have extensive experience to run SOC operations activities listed below as well as Oversees the SOC team. Hand-on experience on implementation / configuration / troubleshooting of various Tech Sec tools Knowledge of Threat Intelligence Platforms to collect and aggregate internal and external sources of information for investigation. Knowledge to analyze Azure AD logs / MDM / Intune / O365 logs / Firewall logs to then correlate with alerts and incidents Ability to independently research and solve technical issues Knowledge of core Information Security concepts related to Governance, Risk & Compliance Demonstrated integrity in a professional environment Excellent team management skills Proven effective verbal and written communication skills Good social, communication and technical writing skills Ability to work in and adapt to a changing environment No. of Openings : 01

One address, no account. We’ll tell you when matching roles go live.

More at MyCrisil

Related open roles

View all roles