Home India Security Operations Specialist

Home India Security Operations Specialist

Security Operations Specialist

Full time at Capgemini in India
Posted on September 7, 2024

Job details

SOC experience/hunt is a strong plus. They must be proficient in Networking, working knowledge of networking concepts such as common TCP/UDP ports, TCP flows, LDAP, authentication, DNS components flow and analysis, response codes and be able to use this knowledge in security investigations. OS Full-Service Management/Troubleshooting and have performed Device Level/SIEM Log Analysis. Recognize threats such as but not limited to DDOS, APT lifecycle (including Data exfiltration attempts). SOC experience Banking / Finance Customer is a must Day to Day Responsibilities of entire team:

  • Providing escalation response for security events including but not limited to intrusion detection, malware infections, denial of service attacks, privileged account misuse and network breaches. Event management includes triage, correlation, and enrichment of individual events to either rule out as false positive, trigger standard detective and corrective responses, or escalating as a security incident.
  • Improving the service level for security operations and monitoring. Creating and maintaining system documentation for security event processing. Expands the usage of security monitoring tools to improve the security of the environment based on business use cases or changes in threat landscape, root causes from security incident response, or output from security analytics
  • Monitoring Security Information and Event Management (SIEM) platform for security alerts, preferably Splunk Enterprise Security.
  • Providing metrics and reports around security monitoring by designing dashboards for asset owners and management consumption. Leveraging existing technologies within the organization to expand the scope of coverage of the security monitoring service.
  • Performs analysis duties, including:
  • Development of Data Dictionaries for log sources to confirm which fields and values are needed or useful for Security Monitoring
  • Review of available logs to confirm there are adequate quantities and content to usefully provide Security Monitoring
  • Triage SIEM alerts to determine False Positive, Incident, or Technology Misconfiguration
  • Perform research at the request of Incident Response teams
  • Recognize IoCs on networks and host machines.
  • Have basic desktop support skills in Windows and Unix environments (ex. password and log locations)
Work Mode: Hybrid Mode

Apply safely

To stay safe in your job search, information on common scams and to get free expert advice, we recommend that you visit SAFERjobs, a non-profit, joint industry and law enforcement organization working to combat job scams.

Share this job
See All Security Jobs
Feedback Feedback