
| Location: | Hyderabad |
| Openings: | 1 |
| Salary Range: |
Description:
As a SOC L2 Consultant you will support the SOC team as the first line of defense to identify potential information security incidents.
Monitor client sources of potential security incidents, health alerts with monitored solutions and requests for information.
This includes the monitoring of real-time channels or dashboards, periodic reports, email inboxes, helpdesk or other ticketing system, telephone calls, chat sessions.
Follow client and incident-specific procedures to perform triage of potential security incidents to validate and determine needed mitigation.
Escalate potential security incidents to client personnel, implement countermeasures in response to others, and recommend operational improvements.
Keep accurate incident notes in case management system.
Maintain awareness of the client’s technology architecture, known weaknesses, the architecture of the security solutions used for monitoring, imminent and pervasive threats as identified by client threat intelligence, and recent security incidents.
Provide advanced analysis of the results of the monitoring solutions, assess escalated outputs and alerts from Level 1 Analysts.
Perform web hunting for new patterns/activities.
Provide end-to-end event analysis, incident detection, and manage escalations using documented procedures.
Devise and document new procedures and runbooks/playbooks as directed.
Assist the Shift Leads and fulfill Shift Lead responsibilities in their absence and maintain monthly SLAs.
Maintain compliance with processes, runbooks, templates and procedures-based experience and best practices.
Provide malware analysis (executables, scripts, documents) to determine indicators of compromise and create signatures for future detection of similar samples.
Continuously improve the service by identifying and correcting issues or gaps in knowledge (analysis procedures, plays, client network models), false positive tuning, identifying and recommending new or updated tools, content, countermeasures, scripts, plug-ins, etc.
Serve as a subject matter expert in at least one security-related area (e.g. specific malware solution, python programming, etc.).
Provide shift status and metric reporting & support weekly operations call.