SOC L2

Capgemini
Posted on
Capgemini logo

Experience
4 - 7 yrs
Salary (CTC)
₹5.2L - ₹5.7L
Job Location
Hyderabad, India
Vacancy
3
Designation
Security Analyst
Job Type
ONSITE

Job Description

Role & responsibilities


Job Summary

Functional responsibilities
• Perform reactive incident analysis to conclusion or prepare it for escallation when needed
• Document the incident analysis to ensure a swift handover to l3 or other incident responders
• Effectively identify threats by performing relevant research and data analysis.
• Transmit security incidents to the appropriate teams for remediation and follow up on the incident to resolution
• Assist end users / Local IT Teams / Applications teams / Infrastructure Support teams in understanding security issues and applying mitigation strategies..
• Execute deep dives and threat hunts beyond the one-of incident tickets and propose corrective actions.
• Follow up on Cyber Threat Intelligence information and suggest detection use cases.

Job Qualifications

Education
• Bachelor's Degree in Computerscience or any related field, but we prefer experience over education
Certifications
• Not Mandatory but its a plus.
Experience
• Prior experience as a network or system administrator is a sereous plus
• 3+ years experience in a SOC analyst role

Specific skills
Keen ability to diagnose and troubleshoot technical issues.
Good understanding of IT Infrastructure landscape and the various components especially active directory, kerberos, adcs
Good knowledge of Windows security logs.
Good understanding of network technologies.
Good understanding of Azure & O365 Cloud and the security technologies around it.
Prior experience with SIEM and EDR tools is manatory, NDR is a plus.
Ability to wite detection queries in any language SPL, EKQL, MS-KQL, ArcSight
Ability to interprete PCAPS
Baisc regex knowledge

Mandatory Skills
Tools:
• Azure Sentinel, Splunk
• Microsoft KQL
• Micrososft E5 security stack: Defender for Endpoint, Defender for Identity, Defender for O365, Defender for CloudApps
• Defender for Cloud
Analysis Skills:
• Malware incident analysis - ability to interprete sandbox results, perform basic static and maldoc analysis.
• Phising campaigns - ability to interprete email headers
• Good knowledge on TTP's used by various threat actors (Mitre Att&ck) and how to detect them.
• Ability to create detection hypothesis and the queries to confirm it.
• Ability to spot repeat alerts and to suggest rule tunings
• Ability to follow existing playbooks but also to suggest improvements on them.

Expected Qualities
• Dynamic and Hands on
• Should be assertive and possess the flexibility to orient him / herself to the demands of the business.
• Strong communication skills and a high degree of energy
• Good analytical and planning skills
• Ability to function effectively in a quality conscious, process driven and extremely productivity driven organization

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.