L
Cyber Security
LTM
๐ฎ๐ณ India
On-site
Mid level
7 months ago
- Vulnerability Management
- Incident Response
- SIEM
- EDR
- triage
- Windows
- Linux
- Active Directory
- Microsoft Sentinel
- Splunk
- Microsoft Defender
- CrowdStrike
- WAF
- ISO 27001
- PCI DSS
- EMC
- Azure
- AWS
- GCP
- Network Security
- DLP
- PowerShell
- Python
- CISSP
- CISM
- CISA
- GCIA
- GCIH
- Defender
- CompTIA Security+
- CySA+
- Threat Intelligence
7 months ago
- Monitor, analyze, and investigate security s using SIEM, EDR, and XDR platforms.
- Lead end-to-end incident response activities including triage, containment, eradication, recovery, and remediation.
- Conduct root cause analysis and post-incident reviews.
- Develop and maintain incident response procedures and playbooks.
- Coordinate with internal stakeholders during security incidents and cyber crisis situations.
- Perform proactive threat hunting using endpoint telemetry, network traffic, and security logs.
- Develop, optimize, and tune detection rules aligned with the MITRE ATT&CK framework.
- Identify advanced threats, malicious activities, and indicators of compromise (IOCs).
- Convert threat hunting findings into actionable detection use cases and security improvements.
- Perform vulnerability assessments and manage enterprise vulnerability scanning activities.
- Assess vulnerabilities for business impact and risk severity.
- Partner with infrastructure, cloud, and application teams to ensure timely remediation.
- Validate vulnerability fixes and ensure SLA compliance.
- Track and report remediation progress to leadership.
- Design, implement, and maintain enterprise security baselines.
- Harden and secure Windows, Linux, Active Directory, Microsoft 365, and cloud environments.
- Support security testing, purple team exercises, and validation assessments.
- Improve security configurations across endpoints, servers, network devices, and cloud workloads.
- SIEM & SOAR Platforms (Microsoft Sentinel, Splunk)
- EDR/XDR Solutions (Microsoft Defender, CrowdStrike)
- Firewalls, IDS/IPS, and Web Application Firewalls (WAF)
- Cloud Security Platforms
- Vulnerability Management Tools
- Support security audits and compliance initiatives.
- Ensure adherence to frameworks such as ISO 27001, NIST CSF, PCI-DSS, and applicable regulatory standards.
- Provide evidence collection, audit support, and compliance reporting.
- Participate in risk assessments and remediation planning.
- Maintain incident response documentation, runbooks, and operational procedures.
- Develop security dashboards and metrics including MTTD and MTTR.
- Prepare executive-level reports on security events, trends, and organizational security posture.
- Present findings and recommendations to senior management.
- Bachelor's degree in Computer Science, Information Security, Cyber Security, Information Technology, or related discipline.
- Master's degree is preferred.
- 7-10 years of hands-on experience in Cyber Security, Security Operations Center (SOC), Incident Response, or Threat Management roles.
- Proven experience managing enterprise-scale security operations and incident response activities.
- EMC Networker
- SIEM Platforms (Microsoft Sentinel, Splunk)
- EDR/XDR Solutions (Microsoft Defender, CrowdStrike)
- Firewalls, IDS/IPS, and Security Monitoring Tools
- Vulnerability Management Platforms
- Windows and Linux Security Administration
- Active Directory Security
- Cloud Security Concepts (Azure, AWS, or GCP)
- Network Security and Security Operations
- MITRE ATT&CK
- NIST Cyber Security Framework (CSF)
- ISO 27001
- PCI-DSS
- Microsoft Defender for Office 365
- Email Security Solutions
- Data Loss Prevention (DLP)
- Imperva Database Activity Monitoring (DAM)
- Security Automation and Detection Engineering
- PowerShell
- Python
- Kusto Query Language (KQL)
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CISA (Certified Information Systems Auditor)
- GCIA (GIAC Certified Intrusion Analyst)
- GCIH (GIAC Certified Incident Handler)
- GCED (GIAC Certified Enterprise Defender)
- Microsoft SC-200
- Microsoft AZ-500
- CompTIA Security+
- CompTIA CySA+
- Incident Response & Crisis Management
- Security Operations Center (SOC) Management
- Threat Hunting & Threat Intelligence
- Detection Engineering
- Risk Assessment & Mitigation
- Vulnerability Management
- Security Architecture & Hardening
- Analytical Thinking & Problem Solving
- Stakeholder Management
- Technical Documentation & Reporting
- Leadership and Team Collaboration
Cyber Security ยท LTM