- Monitor security events from Seceon AI-SIEM, firewalls, IDS / IPS, and endpoint tools in a 24x7 SOC setup.
- Analyze correlated alerts and validate false positives, ensuring high-fidelity alert triage and escalation.
- Perform incident investigation and containment, carrying out malware or network forensics as needed.
- Conduct proactive threat hunting using Seceon SOC automation and AI-driven analytics modules.
- Manage playbooks for incident response workflows and maintain documentation for SOC processes.
- Collaborate with IT infrastructure and application teams to implement mitigation actions after security incidents.
- Recommend Seceon policy fine-tuning including alert rules, threshold calibration, and automated response integration with SOAR.
- Monitor and analyse machine-generated data to detect threats, troubleshoot issues, and improve performance.
- Key responsibilities include creating dashboards and reports, writing search queries (including using SPL), parsing logs, and optimizing data ingestion
- Manual VAPT (Vulnerability Assessment & Penetration Testing)
1. Conduct manual and automated VAPT on web, network, mobile, and infrastructure layers using tools like Burp Suite, Nmap, Nessus, and Metasploit combined with manual testing.
2. Perform threat modeling and post-exploitation testing to validate exploitable weaknesses.
3. Document vulnerabilities with CVE mapping, impact analysis, and actionable remediation strategies.
4. Execute VAPT reporting with both technical and executive summaries tailored for stakeholders.
5. Apply OWASP, NIST, and ISO 27001 standards during assessment and mitigation phases.
Skills and Competencies :
- Hands-on experience with Seceon (AI-powered cybersecurity platform) AI-SIEM, SOAR tools, and integrations involving threat intelligence feeds.
- Proficiency in manual vulnerability discovery, exploit development, and risk analysis.
- Scripting knowledge in Python, or PowerShell for analysis and automation tasks.
- Deep understanding of network security protocols, incident response, and digital forensics.
- Familiarity with incident lifecycle management, MITRE ATT&CK mapping, and IOC correlation.
Qualification and Certifications :
- Bachelors degree in Cybersecurity, Information Technology, or Computer Science.
- 2- 3 years of SOC experience, preferably with Seceon, Q -radar, or similar SIEMs.
Certifications preferred : CEH, OSCP, CompTIA Security+, or Seceon-certified SOC training.
(ref : hirist.tech)