Managed Services Analyst, MXDR
Summary
Monitor and analyze security events using SIEM/XDR tools like Microsoft Sentinel and Check Point Harmony to detect and respond to threats in cloud and on-prem environments.
- Perform vigilant monitoring across various security dimensions, including intrusion detection, file integrity, endpoint protection, log management, and SIEM solutions.
- Leverage expertise in cutting edge XDR solutions, such as Microsoft Sentinel, Microsoft Defender for Endpoint, Check Point Harmony Endpoint, and other solutions.
- Navigate cloud environments, particularly Azure, to ensure comprehensive security coverage.
- Skillfully analyze security events using log data and open-source intelligence to distinguish between legitimate and false-positive incidents.
- Maintain meticulous records of security monitoring activities through efficient case management and ticketing technologies.
- Contribute to the development, implementation, and maintenance of environment-specific rules, alerts, and dashboards within SIEM tools using custom queries.
- Collaborate with clients to tailor and configure SIEM tools, aligning them with specific security and compliance requirements.
- Effectively communicate security alerts to team members and clients regarding anomalies within the environment.
- Apply technical writing prowess to craft formal documentation, including analytical reports and briefings.
- Create and uphold a repository of standard operating procedures, technical documents, training materials, and troubleshooting guidelines for various security solutions.
- Participate in on-call rotations to provide support beyond regular business hours, catering to client operational needs.
- Conduct comprehensive data reviews to evaluate the efficacy of existing security and operational measures.
- Assist in the administration and maintenance of SIEM, Log Management, and Data Analytical Platforms.
- Address customer-initiated requests, such as Log Source configuration, Data Parsing, Use Case Development, and the resolution of complex issues related to managed security services.
- Innovate by developing technical solutions that automate repetitive tasks, enhancing operational efficiency.
- Provide leadership, guidance, and instruction to Junior SOC analysts, fostering a collaborative team environment.
- Manage ticketing processes, including ticket creation, follow-up, and resolution, ensuring timely customer support.
- Employ a combination of tools and analytical skills to investigate and identify the root causes of issues across various technologies.
- Proactively monitor and provide near-real-time updates on the cyber security status, facilitating swift responses to emerging threats and incidents.
- Conduct comprehensive data reviews to evaluate the efficacy of existing security and operational measures.
- Assist in the administration and maintenance of SIEM, Log Management, and Data Analytical Platforms.
- Innovate by developing technical solutions that automate repetitive tasks, enhancing operational efficiency.
- Manage ticketing processes, including ticket creation, follow-up, and resolution, ensuring timely customer support.
- Proactively monitor and provide near-real-time updates on the cyber security status, facilitating swift responses to emerging threats and incidents.
What are we looking for
- Upbeat and positive attitude Strong analytical and troubleshooting skills Excellent written and verbal communication skills
- Team player
- Prior experience performing as a SOC analyst
- Working knowledge of SIEM solutions and incident management solutions
- Technical understanding of core cybersecurity technologies as well as emerging capabilities.
- Inquisitive, problem-solving oriented
- 3+ years of prior relevant experience.
Preferred Qualifications
- Experience:
- SOC: 3+ years (Preferred)
- Cybersecurity: 4+ years (Preferred)
- SIEM: 1+ years (Preferred) (Splunk or Sentinel)
- Vulnerability Management
- Threat Hunting
- Prior SIEM experience (Working Knowledge)
- Tuning
- Alert triage
- Detection Engineering
- Programming/Scripting in one language (PowerShell / Python / Bash)
- One Cyber Security certification (Microsoft SC-900, SC-200, SC-100, Security+, CySA+, CEH, etc)
- Working knowledge of Operating Systems
- Fundamental Networking knowledge
Good to have:
- Advanced certifications in the field of cybersecurity, such as Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM), will be highly regarded.
- Familiarity with threat hunting techniques and the ability to proactively seek out security threats and vulnerabilities.
- Experience with threat modeling and risk assessment methodologies to enhance security strategies.
- Proficiency in scripting or programming languages, such as Python or PowerShell, for automation and customization of security solutions.
- Knowledge of container security, Kubernetes, and cloud-native security best practices.
- Familiarity with security orchestration and automation tools.
- Understanding of identity and access management (IAM) principles and technologies.
- Experience with network security monitoring tools and protocols, including Snort, Suricata, and Bro/Zeek.
- Active involvement in cybersecurity community activities, such as presenting at conferences, contributing to open-source projects, or participating in Capture The Flag (CTF) competitions.
- Strong analytical and problem-solving skills, with the ability to analyze complex security issues and propose effective solutions.
- Knowledge of emerging cybersecurity trends, threats, and mitigation strategies to stay ahead of evolving risks.
- Excellent interpersonal and communication skills, including the ability to convey technical information to non-technical stakeholders effectively.
Location: Bangalore
Work Week: Saturday - Wednesday
Shift Timings: 8 am - 5 pm