About The Company
Tata Communications Redefines Connectivity with Innovation and IntelligenceDriving the next level of intelligence powered by Cloud, Mobility, Internet of Things, Collaboration, Security, Media services and Network services, we at Tata Communications are envisaging a New World of Communications
Job Description
- Responsible for managing customer queries related to all services and solutions delivered, including diagnosing, and resolving complex technical issues in Cloud & Security domain. The role acts as a conduit between customers and other teams such as engineering, architecture etc. for any issue resolution. This is an operational role, responsible for delivering results that have a direct impact on day-to-day operations and capable of instructing professional or technical staff and reviewing the quality of the work undertaken by these roles.
Responsibilities
NG SIEM (SIEM+SOAR+UEBA) Tool Overall Administration, Management, Backup &Archival, Troubleshooting
Upgrade / Update / Patching / Backup / Archival of NG SIEM SolutionMonitor NG SIEM Console & Dashboards and provide response & support to remote SOCteam for Incidents.
Support the day-to-day operation of deployed NG SIEM (SIEM+SOAR+UEBA)Perform initial analysis for known issues and provide the appropriate recommendationsfor closure.
Monitor & Reporting of system components health and take necessary action in case ofany observed issue.
Integration of NG SIEM with IS infrastructure (Existing / Future) but not limited to like IPS,WAF, Patch Management, Firewall, Anti-APT solution, Antivirus, EDR, AD, ERP, DLP,
VMT, Exchange, SharePoint, Network Devices, Web Services, Custom applications etc. &
also on respective version upgrade(s) . -(Continuous)
Develop appropriate use cases / playbooks / models / reports and alerts & develop customparsers / connectors for integrating logs wherever necessary or required. L3 should have
a good command on Regex, Parser & Playbook creation. No separate charges will be
provided for Parser or Play book creation.
Integration of SIEM / SOAR / UEBA Tool with security / non-security solutions based onrequirement & architecture and develop / modify appropriate use cases / rules,
playbooks / models, reports and alerts – (Continuous)
Should provide real time situational awareness to the Client stakeholders.Use and apply learnings from incident and provide recommendation for standardizing theNG SIEM (SIEM+SOAR+UEBA) Solution.
Reduction of False Positives by fine tuning existing correlationrules / configuration / playbooks / models
Automation with continuous improvements, Reduction in MTTR, MTTDDevelop and implement processes for interfacing with Operational teams and othersupporting teams.
Ensure the NG SIEM (SIEM+SOAR+UEBA) integration is intact among the Client SOCsolutions, other assets
Design, create and customize the dashboards / reports as per the Client requirements.Customise & fine tune SIEM, SOAR, UEBA Dashboards.
Ensure the necessary Client SOC documents like operating procedures, configurationmanagement, Low Level Design etc. are up to date with the changes made in their
respective areas.
Automating Day to Day Tasks related with NG SIEM Operations (but not limited to)Above is illustrative list of general activities. All Technology specific activities Related toNG SIEM to be carried out.
Use and apply learnings from incident and provide recommendation for standardizing theNG SIEM Solution.
Support on boarding and maintenance of a wide variety of data sources to include variousOS, appliance, and application logs. Create Custom parser, queries, custom dashboards,
and visualizations
Create and manage NG SIEM knowledge objects to include apps, dashboards, saved andscheduled searches and alerts
Support access requests and modifications and permissionsSupport troubleshooting and remediation of issues as they arise with data ingestion andNG SIEM infrastructure
Creating & updating all SOPs & support for fulfilling Audit requirements.Monitor & report on cyber threats and suggest any changes needed to protect theorganization in SIEM, Leading End-to-End Implementation of the suggested changes.
Provide notification and communication with Incident management and respectiveapplication team upon threat detection.
Perform analysis on the reported incidents, determine the root cause, and recommendthe appropriate solution.
Should have a very good understanding on MITRE att&ck & NIST framework.Work on Improvement of overall posture of NG SIEM deployment to achieve best returnon investment. Coordinate with Analyst team for finetuning & improving NG SIEM overall
utilization / usage & enriching security posture of Client
Desired Skill sets
Good hands on and knowledge to manage SIEM - ArcSight (Micro focus) , SOAR+UEBA - ArcSight(Micro focus)
Good knowledge on implementation, installation, integration troubleshooting and overall functionalitiesExperience in troubleshooting platform related issues, data backup, restoration, retentionMaintains awareness of latest technologies in the domainSkills Required
Ad, Erp, SOAR, Dlp, Arcsight, Antivirus, Firewall, Network Devices, Patch Management, EDR, Exchange, Sharepoint, Regex, Micro Focus, Web Services