Support cyber incident response actions to ensureproper assessment, containment, mitigation and documentation
Perform in-depth analysis and investigative effortswhen events are escalated and determine next appropriatecontainment/remediation/eradication efforts.
Research and Evaluate new technologies like Anti APTsolutions, SOAR, ,Deception technologies, Big Data forensic analytic tools, andassist in implementation of the same.
Assist with defining and updating incident responseplaybooks to ensure tasks align with best practice
Identify and propose areas for improvement within theSecurity Operations Centre.
Responsible for driving execution of daily, weekly,and monthly metrics for statistical threats and KPIs.
Coordinate with global stakeholder along with theSenior management during contingency scenarios/ high severity incidents toensure responsive actions are communicated in timely manner.
ProfileDescription:
Should have 7-11 years of specific InformationSecurity experience.
Should have subject matter expertise in relevantareas, such as Incident Response, Forensic analysis, Malware analysis,Intrusion analysis and Crisis Management.
Strong working knowledge on security tools, such asSIEM,AV,Vulnerability scanners,Proxies,WAF,Net flow,IDS and Forensic Tools.
In-depth knowledge of malware families and networkattack vectors
Demonstrated experience in an enterprise-levelincident response team or security operations centre.
Log (network, security, access, OS, application, etc.) analysis skills and experience in relation to identifying and investigatingsecurity incidents.
Strong knowledge of Operating System Internals (Linux,Windows. Etc)
Should be familiar with security engineeringpractises, web/Application security, Cloud Security.
Should have Scripting knowledge ()
Have sound analytical and problem solving skills
Preferable be a GIAC,CISSP, CEH certified Professional
Experience in product suites like Mcafee, Fireye,Crowd Strike, Cylance etc.
Job Classification
Industry: IT Services & ConsultingFunctional Area / Department: IT & Information SecurityRole Category: IT Infrastructure ServicesRole: Incident ManagementEmployement Type: Full time