Analyst (Support & Operations)
Technology, Data & Digital · IT Infrastructure & Security · Cybersecurity · IT Support
In short
The L2 Security Analyst in Delhi, India, will monitor, investigate, and respond to identity-based and endpoint security threats using Microsoft Defender for Endpoint, requiring 24x7 support and global team collaboration. Responsibilities include threat detection, containment, remediation, and providing detailed security analysis reports.
Responsibilities
- Real-time monitoring, investigation, and response to identity-based and endpoint security threats using Microsoft Defender for Endpoint (MDE).
- 24x7 support coverage and collaboration with global security teams.
- Ensure threat detection, containment, and remediation in a fast-paced environment.
- Work with large and complex networks.
- Experience with SIEM tools or Intrusion Detection systems (IDS) platforms and Network Security roles.
- Exposure to Mitre framework and equivalent.
- Hands-on experience in EDR platforms and threat analysis, threat hunting/incident response.
- Experience and knowledge in Network security/System Security/Endpoint Security.
- Experience of Event Monitoring and analysis and escalations.
- Provide inputs for content management.
- Experience on Monthly, Weekly and daily reporting.
- Review SIEM escalated incidents and qualify true positives.
- Provide a monthly trend and security analysis summary report.
- Provide SIEM event/Incident analytics support.
- Provide log analysis summary and recommendations on detection/protection of incidents.
- Perform advanced triages and collaborate with resolved groups, third parties, or designated customer contacts.
- Liaise between cross-functional teams and assist in formulating security incident response reports.
- Advocate protection and mitigation strategies from lessons learned exercises.
Requirements
- Ability to work with very large and complex network.
- Self-motivated individual and creative thinker who will take ownership of tasks and projects, able to work with the team, and manages tasks effectively and has a proven track record of consistent and organized outputs.
- Eagerness to understand complex problems and requirements, an aptitude for translating these problems into workable designs and solutions and will possess a keen eye for detail.
- Knowledge/experience on any SIEM tools or Experience on IDS (Intrusion Detection systems) platform and Network Security roles.
- Exposure to Mitre framework and equivalent, Hands-on experience in EDR platforms and threat analysis, threat hunting/incident response experience.
- Experience and knowledge in Network security/ System Security/ Endpoint Security.
- Experience of Event Monitoring and analysis and escalations.
- Willing to work on 24/7 operations.
- Good verbal/written communication skills.
- Willing to work in 24x7 environments.
- Incumbent should carry continual system improvement mindset and able to demonstrate in work.
- Client facing technical analysis report and presentation skills.
Desired Qualifications
- Provide inputs for content management.
- Provide a monthly trend and security analysis summary report.
- Provide SIEM event/Incident analytics support.
- Provide log analysis summary and recommendations on detection/protection of incidents.
- Perform advanced triages and work in collaboration with resolved groups, third party or with designated customer contacts.
- Liaise between cross functional teams and assist in formulating security incident response report.
- Advocate protection and mitigation strategies to be implemented from lessons learnt exercises.
Benefits
- From time-to-time travel opportunities may be assigned.
#L2 Security Analyst#identity-based security threats#endpoint security threats#Microsoft Defender for Endpoint#threat detection#threat containment#threat remediation#24x7 support#global security teams#SIEM tools#Intrusion Detection systems#Network Security#Mitre framework#EDR platforms#threat analysis#threat hunting#incident response#Network security#System Security#Endpoint Security#Event Monitoring#escalations#content management#reporting#log analysis#triages#security incident response#mitigation strategies#lessons learned#verbal communication#written communication#client facing#technical analysis report#presentation skills#system improvement#HCLTech