Analyst (Support & Operations)

Teknik, data och digitalt · IT-infrastruktur och säkerhet · Cybersäkerhet · DevOps

I korthet

The L2 Security Analyst will monitor, investigate, and respond to security threats using Microsoft Defender for Endpoint. This role requires 24x7 support, collaboration with global teams, and expertise in SIEM, SOAR, and various security platforms.

Ansvarsområden

  • Real-time monitoring, investigation, and response to identity-based and endpoint security threats using Microsoft Defender for Endpoint (MDE).
  • Ensure threat detection, containment, and remediation in a fast-paced environment.
  • Provide 24x7 support coverage.
  • Collaborate with global security teams.
  • Work with very large and complex networks.
  • Review SIEM escalated incidents and qualify true positives.
  • Provide a monthly trend and security analysis summary report.
  • Provide SIEM event/Incident analytics support.
  • Provide log analysis summary and recommendations on detection/protection of incidents.
  • Perform advanced triages and work in collaboration with resolved groups, third party or with designated customer contacts.
  • Liaise between cross-functional teams and assist in formulating security incident response reports.
  • Advocate protection and mitigation strategies to be implemented from lessons learned exercises.

Krav

  • Ability to work with very large and complex networks.
  • Self-motivated individual and creative thinker who will take ownership of tasks and projects, able to work with the team, and manages tasks effectively and has a proven track record of consistent and organized outputs.
  • The ideal candidate will demonstrate an eagerness to understand complex problems and requirements, an aptitude for translating these problems into workable designs and solutions and will possess a keen eye for detail.
  • Knowledge/experience on any SIEM tools or Experience on IDS (Intrusion Detection systems) platform and Network Security roles.
  • Exposure to Mitre framework and equivalent.
  • Hands-on experience in EDR platforms and threat analysis, threat hunting/incident response experience.
  • Experience and knowledge in Network security/ System Security/ Endpoint Security.
  • Experience of Event Monitoring and analysis and escalations.
  • Provide inputs for content management.
  • Experience on Monthly, Weekly and daily reporting.
  • Willing to work on 24/7 operations.
  • Good verbal/written communication skills.
  • Willing to work in 24x7 environments.
  • Incumbent should carry continual system improvement mindset and able to demonstrate in work.
  • Client facing technical analysis report and presentation skills.

Önskade kvalifikationer

  • The ideal candidate will demonstrate an eagerness to understand complex problems and requirements, an aptitude for translating these problems into workable designs and solutions and will possess a keen eye for detail.

Förmåner

  • From time-to-time travel opportunities may be assigned.
#SOC#SIEM#SOAR
HCLTech Logo

Företag

HCLTech

Publicerade jobb

för 2 veckor sedan

Anställningstyp

Heltid

Arbetsform

På plats

Erfarenhetsnivå

Mellannivå

Platser

Madurai, India

Sökande

Ansök tidigt