Required Skills
Behavioral | Aptitude | Communication
Technology | Cybersecurity | End Point Security
Technology | Cybersecurity | SOC Alert Management
OVERALL SKILL SETS FOR End Point
- Experience in endpoint protection troubleshooting
- The security specialist is responsible for conducting information security investigations as a result of security incidents
- Provide timely detection, identification, and alerting of possible attacks / intrusions,
- Anomalous activities, and misuse activities and distinguish these incidents and
events from benign activities.
Isolate and remove malware.Conduct research, analysis, and correlation across a wide variety of all sourceData sets (indications and warnings).Provide daily summary reports of network events and activity relevant to cyberdefense practices.
Receive and analyze network alerts from various sources and determine possiblecauses of such alerts.
Notify designated managers, cyber incident responders and articulate the event'shistory, status, and potential impact for further action in accordance with the
organization's incident response plan.
Work with stakeholders to resolve computer security incidents and vulnerabilitycompliance.
Malware handling on AVHost Intrusion Detection and Prevention (HIPS)Monitor security of the cloud and on-perm environment using various security toolsRetrieve and report metrics on various security areas of the cloud on-perm environment.Install and configure security systems and tools.Behavioral analysis and actionable intelligence applied to stop an incident from breachEnsuring that service reports are produced for each customer service and that breaches of SLA targets are highlighted, investigated and actions taken to prevent their recurrenceJob Requirements
Good understanding of system security (client, server, system hardening standards)Notion of networking concepts (routing, switching, proxy, firewall) and ability to assist SOC analysts with threat detection systems (networks, firewalls, servers, Windows, Linux, authentication etc.).Ability to identify, analyze and report root cause of security incidentsRespond to security escalations and coordinate with internal, external and vendor support in order to provide initial analysis, containment, remediation, after action analysis and reporting of security events and incidents.Ability to use email / web / network / security tools / systems logs to analyze ongoing incidents / define mitigation actions / conduct investigationsCreative, dynamic, open minded, pro-active, and enthusiasticResult-focused, able to work under pressureHonest, willing, and able to take the lead and to delegate tasks where necessaryShould be comfortable working in 24 / 7 shiftsDesired Skills
Trend Micro – EPS, Antivirus management (crowd strike Falcon) , Symantec Endpoint ProtectionRoles and Responsibilities :
Major Responsibilities :
Lead the technical deployment or troubleshooting on any of two products - Symantec,TrendMicro server security and TrendMicro EDRImplement project / change and troubleshoot incidents spanning various Antivirus vendor products involving Symantec, TrendMicro Server Security and EDRImplement project / change and troubleshoot incidents on Anti malware solutionsAdherence to ITIL service management frameworkMonitor / manage the customer perimeter security infrastructure as per the Service LevelAgreement (SLA) with minimal escalations.Vulnerability Management of the managed infrastructure with appropriate remediationApply investigation techniques to document root cause and impact of detected computer security incidents.Performs or assists with IT security assessments or audits of internal and external networks and systems under the direction of the IT Security management. Document findings in written reports with recommendations for remediation.Assists with the development and documentation of an overall IT Security architecture to assure confidentiality, integrity and availability of company IT assets.Develops and maintains good communications and working relationships with teams and external clients.Knowledge on Cyber security incidents and reacting to it in a most optimal and secured way. Driving the Mitigation.Identifying and mitigating the risks in the IT environment we manage.Providing inputs to the Continual Service improvements and driving the Service improvement plans and the Hygiene Projects.Actively giving inputs to Automating various tasks and driving the required projects.Provide on-call support as per rotation for emergency situations.