SOC Engineer- L3
Globals
- Bangalore, Karnataka
- Permanent
- Full-time
- Expertise in implementing, configuring, and maintaining SOC solutions, including SIEM, HIPS/NIPS, Network Monitoring tools, and other advanced security technologies.
- Expertise in Incident Management and Response
- Strong and In-depth knowledge of security concepts such as cyber-attacks and techniques, threat vectors, Threat Hunting, Threat Intelligence, Advanced Threat Detection and Analysis, Forensic analysis, Network security, endpoint security, Cloud security risk management, incident management, etc.
- Strong hands-on experience in security device management, security monitoring setup, and integration of security tools.
- Develop and refine incident response playbooks, integrating them with SOC processes and ensuring they reflect the latest threat intelligence.
- Lead the implementation and optimization of threat detection systems, including UBEA, AV, Web Security, and cloud security monitoring.
- Develop automated workflows and integrations to streamline SOC processes and improve incident response times.
- Collaborate effectively with internal SOC teams and external stakeholders to enhance security measures.
- Present regular metrics and reports on daily incidents as well as emerging security issues.
- Proficiency in developing and using incident response playbooks.
- Ability to coordinate and lead incident response efforts during security incidents.
- Strong written and verbal communication skills for creating incident reports and communicating effectively with both technical and non-technical stakeholders.
- Ability to collaborate with different teams within the SOC and with external stakeholders.
- Capability to lead and guide junior analysts during incident response and daily operations.
- Willingness to mentor and share knowledge with less experienced team members.
- Proactive attitude toward staying updated on the latest cybersecurity threats, vulnerabilities, and industry best practices.
- Understand legal and regulatory requirements related to data protection and cybersecurity.
- Strong analytical and problem-solving skills to identify and address complex security incidents.
- Knowledge of security devices and their management.
- Experience in setting up SOC processes.
- Knowledge about various tools like – SIEM, SSL, Packet Analysis, HIPS/NIPS, Network Monitoring tools, Remedy, Service Now Ticketing Toolset, Web Security, AV, UBEA, Advanced SOC
- Minimum of 5 years of experience in Cybersecurity, SOC, or a relevant discipline
- Knowledge of security concepts such as cyber-attacks and techniques, threat vectors, risk management, incident management, etc.
- Knowledge of TCP/IP Protocols, network analysis, and network/security applications
- Proficiency in developing and using incident response playbooks and automated SOC processes.
- Experience in Open-Source tools as well as Commercial tools
- Proactive attitude towards enhancing SOC capabilities and addressing emerging security challenges.
- Excellent written and verbal communication skills for incident reporting and stakeholder engagement.
- Ability to lead incident response efforts and guide junior analysts during security incidents.
- Proficient in Incident Management and Respons
- Previous experience working in a Security Operations Centre (SOC), dynamic and/or malware analysis
- Complete understanding of firewalls, proxies, SIEM, antivirus, and IDPS concepts.
- Ability to identify and mitigate network vulnerabilities and explain how to avoid them.
- Understanding of security standards, regulatory requirements, and best practices.
- Understanding of patch management with the ability to deploy patches promptly while understanding business impact.
- BE/ B.Tech/ M.Tech/ MSc/ MCA qualification CS/IS/E&C or equivalent