Manage all aspects of Security Incident Response and Threat Hunting including validation, monitoring, containment, log analysis, system forensic analysis, and reporting.
Work closely with SOC Manager and business stakeholders to meet project deliverables.
Carrying out post-incident reviews, assessing the effectiveness of controls, detection and response capability, and supporting the required improvements with the responsible owners.
Should be expertise in Creation of SOP and Playbook.
Routinely brief and update senior leadership and other stakeholders on the active incidents and manage expectation.
Requirements
8+ years’ experience of working in IT Security and relevant areas like Security Operations Centre, Incident Response, Threat Intelligence, Digital Forensics, Threat Hunting, Malware Analysis etc.
Should have experience to handle Incident Response for diverse financial organization environment.
Proven experience in handling security events in mission critical environments, hands-on troubleshooting, analysis, and technical expertise to guide team members in resolution of incidents as per agreed SLA.
In depth understanding of incident response frameworks such as NIST and SANS.
Strong knowledge of enterprise detection technologies and processes (Advanced Threat Detection Tools, IDS/IPS, Network Packet Analysis, Endpoint Protection)
Should have hands-on experience with utilizing Cloud based SIEM/EDR/NDR, Elasticsearch etc. and help team in investigating security issues and/or complex operational issues.