freehire launches on Product Hunt on 26 August.

Follow →

Managed Services Analyst, MXDR

Summary

Monitor and analyze security events using SIEM/XDR tools like Microsoft Sentinel and Check Point Harmony to detect and respond to threats in cloud and on-prem environments.

  • Perform vigilant monitoring across various security dimensions, including intrusion detection, file integrity, endpoint protection, log management, and SIEM solutions.
  • Leverage expertise in cutting edge XDR solutions, such as Microsoft Sentinel, Microsoft Defender for Endpoint, Check Point Harmony Endpoint, and other solutions.
  • Navigate cloud environments, particularly Azure, to ensure comprehensive security coverage.
  • Skillfully analyze security events using log data and open-source intelligence to distinguish between legitimate and false-positive incidents.
  • Maintain meticulous records of security monitoring activities through efficient case management and ticketing technologies.
  • Contribute to the development, implementation, and maintenance of environment-specific rules, alerts, and dashboards within SIEM tools using custom queries.
  • Collaborate with clients to tailor and configure SIEM tools, aligning them with specific security and compliance requirements.
  • Effectively communicate security alerts to team members and clients regarding anomalies within the environment.
  • Apply technical writing prowess to craft formal documentation, including analytical reports and briefings.
  • Create and uphold a repository of standard operating procedures, technical documents, training materials, and troubleshooting guidelines for various security solutions.
  • Participate in on-call rotations to provide support beyond regular business hours, catering to client operational needs.
  • Conduct comprehensive data reviews to evaluate the efficacy of existing security and operational measures.
  • Assist in the administration and maintenance of SIEM, Log Management, and Data Analytical Platforms.
  • Address customer-initiated requests, such as Log Source configuration, Data Parsing, Use Case Development, and the resolution of complex issues related to managed security services.
  • Innovate by developing technical solutions that automate repetitive tasks, enhancing operational efficiency.
  • Provide leadership, guidance, and instruction to Junior SOC analysts, fostering a collaborative team environment.
  • Manage ticketing processes, including ticket creation, follow-up, and resolution, ensuring timely customer support.
  • Employ a combination of tools and analytical skills to investigate and identify the root causes of issues across various technologies.
  • Proactively monitor and provide near-real-time updates on the cyber security status, facilitating swift responses to emerging threats and incidents.
  • Conduct comprehensive data reviews to evaluate the efficacy of existing security and operational measures.
  • Assist in the administration and maintenance of SIEM, Log Management, and Data Analytical Platforms.
  • Innovate by developing technical solutions that automate repetitive tasks, enhancing operational efficiency.
  • Manage ticketing processes, including ticket creation, follow-up, and resolution, ensuring timely customer support.
  • Proactively monitor and provide near-real-time updates on the cyber security status, facilitating swift responses to emerging threats and incidents.

What are we looking for

  • Upbeat and positive attitude Strong analytical and troubleshooting skills Excellent written and verbal communication skills
  • Team player
  • Prior experience performing as a SOC analyst
  • Working knowledge of SIEM solutions and incident management solutions
  • Technical understanding of core cybersecurity technologies as well as emerging capabilities.
  • Inquisitive, problem-solving oriented
  • 3+ years of prior relevant experience.

Preferred Qualifications

  • Experience:
    • SOC: 3+ years (Preferred)
    • Cybersecurity: 4+ years (Preferred)
    • SIEM: 1+ years (Preferred) (Splunk or Sentinel)
  • Vulnerability Management
  • Threat Hunting
  • Prior SIEM experience (Working Knowledge)
    • Tuning
    • Alert triage
    • Detection Engineering
  • Programming/Scripting in one language (PowerShell / Python / Bash)
  • One Cyber Security certification (Microsoft SC-900, SC-200, SC-100, Security+, CySA+, CEH, etc)
  • Working knowledge of Operating Systems
  • Fundamental Networking knowledge

Good to have:

  • Advanced certifications in the field of cybersecurity, such as Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM), will be highly regarded.
  • Familiarity with threat hunting techniques and the ability to proactively seek out security threats and vulnerabilities.
  • Experience with threat modeling and risk assessment methodologies to enhance security strategies.
  • Proficiency in scripting or programming languages, such as Python or PowerShell, for automation and customization of security solutions.
  • Knowledge of container security, Kubernetes, and cloud-native security best practices.
  • Familiarity with security orchestration and automation tools.
  • Understanding of identity and access management (IAM) principles and technologies.
  • Experience with network security monitoring tools and protocols, including Snort, Suricata, and Bro/Zeek.
  • Active involvement in cybersecurity community activities, such as presenting at conferences, contributing to open-source projects, or participating in Capture The Flag (CTF) competitions.
  • Strong analytical and problem-solving skills, with the ability to analyze complex security issues and propose effective solutions.
  • Knowledge of emerging cybersecurity trends, threats, and mitigation strategies to stay ahead of evolving risks.
  • Excellent interpersonal and communication skills, including the ability to convey technical information to non-technical stakeholders effectively.

Location: Bangalore

Work Week: Saturday - Wednesday

Shift Timings: 8 am - 5 pm

See also