
Lead IT Security Analyst
- Pune, Maharashtra
- Permanent
- Full-time
- Conducts forensic investigations on compromised systems to identify the root cause of security incidents and remediation actions that need to be taken.
- Correlate incident data to identify specific vulnerabilities and make recommendations that enable swift remediation
- Making recommendations that improve ACI's endpoint security posture.
- Overall responsibility for Security Operations to handle threat detection and response.
- Conducts internal and external investigations and responds to internal and external security threats
- Contribute to policy development and prepare briefings to explain security programs and requirements to senior executives.
- Providing expert technical advice, guidance, and recommendations to management and other technical specialists on critical information technology security issues.
- Assessing risk factors and advice on vulnerability to attack from a variety of sources, and procedures for the protection of systems and applications.
- Proposing and implementing security measures that align with FFIEC, IRS, PCI, HIPAA, and other Federal regulations and guidance.
- Interpreting internal policy and implementation, and documentation of those requirements.
- Develop System Security Plans, Security Assessment Reports, Continuous Monitoring Plans, and Plans of Action & Milestones.
- Ensure coordination and collaboration on security activities.
- Effectively communicate both orally and in writing with management and other technical specialists.
- Proposes and helps review security plans and policies to improve the security environment.
- Maintains metrics, operational playbooks, process diagrams, and documentation for security monitoring and response.
- Obtains information and stays up to date on the latest threats and security trends in a fast and efficient way to keep the enterprise environment protected.
- Plan, organize, and manage tasks on time with minimal supervision.
- Oversees, responds to, and remediates all escalated SIEM events from on-premise and cloud systems.
- Obtains information and stays up to date on the latest threats and security trends in a fast and efficient way to keep the enterprise environment protected.
- Other duties may be assigned as needed to address new security threats facing the enterprise environment.
- Provides off-hour support as needed for security monitoring and response activities.
- Understand and adhere to all corporate policies to include but not limited to the ACI Code of Business Conduct and Ethics.
- A bachelor's degree in Computer Science or a related technical discipline, or the equivalent combination of education, technical certifications or training, or equivalent work experience, is required.
- 7+ years' experience in Information Security.
- Must have experience in incident response and management.
- Demonstrated experience with Windows and non-Windows server configuration, administration, and monitoring.
- Experience supporting large enterprise IT environments.
- Experience creating, modifying, and following standard procedural documents.
- Excellent written and verbal communication skills.
- Ability to multitask in a dynamic environment
- Analytical thought process.
- Project management.
- Knowledge of the Jira ticketing platform.
- Working experience with Information Security, Network Security, Insider threat, Security Monitoring, Incident Response, and Vulnerability Management.
- Working experience with industry-standard security technologies and services Firewalls, VPN, IDS, Endpoint Security, AV, Proxy, and SIEM.
- Strong experience with SIEM event/log analysis and correlation.
- CISSP or equivalent
- Ethical Hacking Certification (a plus)
- Standard work environment.
- The majority of time is spent sitting and on a PC (Phys. Req.).
- Weekend and off-hours support may be required periodically