https://bayt.page.link/Gig1EWSLcYQ3ZwKL8
أنشئ تنبيهًا وظيفيًا للوظائف المشابهة

الوصف الوظيفي

Introduction
A career in IBM Consulting is rooted by long-term relationships and close collaboration with clients across the globe.
You’ll work with visionaries across multiple industries to improve the hybrid cloud and AI journey for the most innovative and valuable companies in the world. Your ability to accelerate impact and make meaningful change for your clients is enabled by our strategic partner ecosystem and our robust technology platforms across the IBM portfolio; including Software and Red Hat.
Curiosity and a constant quest for knowledge serve as the foundation to success in IBM Consulting. In your role, you’ll be encouraged to challenge the norm, investigate ideas outside of your role, and come up with creative solutions resulting in ground breaking impact for a wide network of clients. Our culture of evolution and empathy centers on long-term career growth and development opportunities in an environment that embraces your unique skills and experience.

Your Role and Responsibilities
As a SOC Engineer (L2) would work to be responsible for below activities:
  • EDR alert monitoring.
  • Performing TI based and hypothesis driven threat hunting oriented to SIEM logs.
  • Support the incident response team during major security incident with advance investigation skills.
  • Closely work with SOC team and be responsible for incident detection, triage, analysis and response.
  • Handle L2 and above level technical escalations from L1 Operations team and resolve within SLA.
  • Finetune of existing use case of SIEM to reduce false positive.
  • Perform and reviews tasks as identified in a daily task list.
  • Report Generation and Trend Analysis.
  • Walkthrough of the daily, weekly, and monthly SOC reports to the customer/stake holders.
  • Ready to work in 24×7 rotational shift model including night shift.
  • Identify the process and technology gaps and drive for closure.
  • Explore different technologies available in the security industry.
  • Analyse and tune threat monitoring dashboards.
  • Coordination with internal customers for their security related problems and providing solutions.
  • Create and manage various KEDBs the SOPs, runbooks, asset inventory with risk classification, critical application flow diagram, network flow diagram, privileged user list.
  • Mentor and monitor L1 team members for their daily activities.
  • Provide KT and required training to other team members.


Required Technical and Professional Expertise


  • 2 to 3 + years of IT experience in security with at least 2+ Years in Security Operation centre with SIEMs and EDR.
  • Good to have hands on experience with managing SIEM solutions on public/private clouds like Amazon AWS, Microsoft Azure, etc.
  • Proven Experience on any of the Security information and event management (SIEM) tools like (Qradar, Splunk, McAfee ESM etc.)
  • Data-driven threat hunting using SIEM and other threat hunting tools.
  • Experience is SOAR tools such as Qradar Resilient, PaloAlto XSOAR
  • Identify quick defence techniques till permanent resolution.
  • Recognize successful intrusions and compromises through review and analysis of relevant event detail information.
  • Launch and track investigations to resolution. Recognize attacks based on their signatures, differentiates false positives from true intrusion attempts.
  • Actively investigates the latest security vulnerabilities, advisories, and incidents.
  • Identify the gaps in security environment & suggest the gap closure.
  • Drive & Support Change Management.


Preferred Technical and Professional Expertise


  • Certifications: CEH or ECIH or CompTIA security analyst.
  • Ambitious individual who can work under their own direction towards agreed targets/goals and with creative approach to work.
  • Intuitive individual with an ability to manage change and proven time management.
  • Proven interpersonal skills while contributing to team effort by accomplishing related results as needed.
  • Up-to-date technical knowledge by attending educational workshops, reviewing publications.
  • Any entrant or Professional skill on shell scripting, AIX, Linux or Python.

تفاصيل الوظيفة

منطقة الوظيفة
بونة الهند
قطاع الشركة
خدمات الدعم التجاري الأخرى
طبيعة عمل الشركة
صاحب عمل (القطاع الخاص)
نوع التوظيف
غير محدد
الراتب الشهري
غير محدد
عدد الوظائف الشاغرة
غير محدد
لقد تجاوزت الحد الأقصى لعدد التنبيهات الوظيفية المسموح بإضافتها والذي يبلغ 15. يرجى حذف إحدى التنبيهات الوظيفية الحالية لإضافة تنبيه جديد
تم إنشاء تنبيه للوظائف المماثلة بنجاح. يمكنك إدارة التنبيهات عبر الذهاب إلى الإعدادات.
تم إلغاء تفعيل تنبيه الوظائف المماثلة بنجاح. يمكنك إدارة التنبيهات عبر الذهاب إلى الإعدادات.