Job Title: SOC Analyst
Location: Pune
Department: Security Operations Center (SOC)
About the Role
We are looking for a motivated and enthusiastic SOC Analyst to join our Cybersecurity team. This role offers an excellent opportunity to gain hands-on experience in Security Operations, Cloud Security, Incident Response, SIEM, and Web Application Security.
Role Description :
- Opportunity to work across key security domains (such as Cloud, zero trust, Identity & Access, Data)Β
- Deployment of Security services like WAF, BOT protection, and Anti-DDoS (L3/L7) working in close conjunction with security architecture, vendors, and internal stakeholders.
- Contribute to global strategy work and process of onboarding of applications and APIs behind security controls.
- Monitor and manage the health of WAF/BOT/DDoS security controls. Maintain good security posture Develop, maintain, test, and troubleshoot policies and rule sets globally. Monitors systems activities and fine-tune system parameters and configuration to optimize performance and ensure the security of systems.
- Respond to security events and contribute to incident response plans.
- Review and respond to WAF/BOT/DDoS alerts, onboard new apps to these security controls, optimize policies, lead/conduct upgrades, integrate with monitoring/alerting tools, and troubleshoot issues.
- Support operational tasks for WAF/BOT/DDoS to assist, solve, and advise on issues associated with WAF/BOT/DDoS services within prescribed SLA. Support on-call rotation. Open vendor support cases as required and track to closure.
- Security enthusiast with strong hands-on experience and broad knowledge across the security domain.
- The ideal candidate should have knowledge of various security tools and services and will be a part of a managed SOC team.
- Preferred Knowledge of security domains related to monitoring & response, perimeter security, cloud security, application security, endpoint security, network security, data security, risk & compliance, and hands-on experience on at least one SIEM.
Roles and responsibilities:
- Responsible for 24x7 alerts monitoring and tracking Incidents on SIEM and EDR, reporting & escalation, regular SIEM administration, enforcement of network & cloud security policies, research on new security technologies for integrating them in SOC, along with the security monitoring & log analysis of multi-vendor security solutions
- Configuring monitoring policies, alerts, procedures, and standards relating to SOC practices for the security domains viz. network security, perimeter security, cloud security, data security, zero trust, etc.
- Identify security measures to improve incident response.
- Respond to security incidents.
- Should be able to coordinate incident response across teams.
- Should be able to perform security assessments and audits.
- Should be able to provide technical solutions to security vulnerabilities.
- Research new attack vectors.
- Providing frontline support for applications and their infrastructure
- Respond, troubleshoot, and provide resolution to the production alerts.
- Analyse trends to proactively prevent incidents.
- Assist in security vulnerability and remediation.
- Participation in an on-call rotation and operating effectively in a global 24x7 environment
- Ability to learn new technologies quickly with some support and guidance
- Troubleshoot incidents, identify root cause, fix and document problems, and implement preventive measures
- Participate in innovation and developing monitoring systems smarter
- Automated response to security incidents (malware infections, unauthorized access, malicious emails, DDoS attacks, etc, together with evaluating the type, nature and severity of security events (security assurance/security compliance) through the use of a range of security event analysis tools.
- Assess security technologies and data in place to propose relevant Security use cases (mostly from a security incidents monitoring perspective)
Technical Understanding :
- Domain knowledge of web applications, and associated protocols (HTTP/S, SSL, DNS, TCP/IP)
- Familiarity with common web application security concepts such as the OWASP Top 10.
- Various Monitoring Services and tools like CloudWatch, Grafana, New RelicΒ
- AWS Security Services.
- WAF (WAAP): Working knowledge of WAF, API, Bot Control, and Exposure to technology platforms - AWS WAF, F5, Imperva, technology is required.
- Understanding of DDoS attacks on Layers 3,4, and 7
- Proficiency with popular tools in the industry of AppSec and their usage: Burp Suite, Postman, Wireshark