Key Responsibilities
- Manage and successfully deliver ISSQUARED SOC services to external customers in a shared or dedicated model.
- Leadership and Management of the SOC team including hiring, developing & retaining personnel, workload assignment, process development, project management
- Work with sales and pre-sales teams to develop and present the SOC and other cyber security offerings to potential customers.
- Develop standard operating procedures and other appropriate documents to enforce quality and consistency of Security services being delivered.
- Stay in touch with the latest exploits and fixes and be tuned to lead the team on effective zero-day exploit situations.
- Analyse event streams from the SIEM tools and recommend / implement optimum tuning features to ensure that analysts and agents are not loaded with a high number of false positives.
- Able to technically design, manage & configure
- SIEM tools like QRADAR, Crowdstrike, FortiSIEM, Microsoft Sentinel.
- Firewalls & IDS / IPS solutions
- VAPT tools and processes
- Adherence to all SLAs and committed to the principle of zero events being missed.
- Setup, lead and drive to closure SSIRT calls, lead forensic analysis activities with on-shore counterparts and other technical managers / leads.
- Work closely with other teams like the NOC, L3 escalation support teams to drive cohesive responses to major issues.
- Identify custom reporting requirements, translate requirements into SIM technical specifications.
- Ensure shifts are staffed appropriately and right resources are recruited as per business needs.
- Contribute to improving the delivery processes and metrics.
- Contribute to training and development of documentation required to support the service.
- Work closely with engineering teams to refine the monitoring solutions and processes deployed leading to efficiencies.
- Be able to create dashboards and reports, set up calls with customers and present daily, weekly and monthly trends and performance statistics.
Essential Attributes and Skills Needed :
Fluency in spoken and written English with minimal or no MTI influence.Bachelors degree in Science or higher. (B.E / B.Tech preferred).In-depth knowledge of security concepts such as Cyber-attacks and techniques, threat vectors, risk management, incident management etc.Experience in security device Management and SIEM toolsKnowledge of applications, databases, middleware to address security threats against the same.Proficient in preparation of reports dashboards and documentation.Good Analytical skills, problem solving and Interpersonal skills.Solid and demonstrable comprehension of information security including malware, emerging threats, attracts, and vulnerability managementExperience with reviewing raw log files, data correlation, and analysis (i.e firewall, network flow, IDS, system logs) including integration and workflow experience with Security automation and orchestrations platforms.Subject matter expert(SME) in one or multiple areas such as Windows, UNIX, mid-range, mainframe, firewalls, intrusion detection, Endpoint Detection and Response, threat detection analysis and / or information risk management.Skills Required
intrusion detection, Vulnerability Management, Incident Management, Siem, Information Security, threat management , Firewall