MDR security expert
On-siteGhāziābād, Uttar Pradesh, India
Job Summary
Design, develop, and deliver end-to-end cybersecurity use-cases to enhance detection and response capabilities for security operations centers using multivendor SIEM, SOAR, and EDR solutions. Build a library of risk-driven cyber-attack scenarios covering the entire kill chain, including reconnaissance, weaponization, and delivery, with clear identification of threats, vulnerabilities, and remediation workflows. Support the business line as a subject matter expert for cyber management, detection, and response across IT, Telecom Core Network, and Telecom Radio Access Network domains. Create technical documentation, presentations, and training materials for key stakeholders. Integrate existing commercial and open-source threat detection and response tools while optimizing detection rules and response playbooks.
Required Qualifications
- Masters or bachelor's degree in computer science or related field such as cyber security or computer forensic
- 7+ years of relevant experience
- Minimum of 5 or more years of relevant experience in field of cybersecurity domain in manage, detection and response (MDR)
- Understanding and working knowledge of SOC technologies such as SIEM, SOAR, EDR, etc.
- Experience with SIEM tools, in terms of scripting, tuning and optimization of threat detection rule sets
- Experience with SOAR tools, in terms of scripting, tuning and optimization of threat response playbooks and workflows
- Knowledge on MITRE ATT&CK framework, TTPs used in various types of attacks
- High level of personal integrity, as well as the ability to professionally handle confidential matters and show an appropriate level of judgment and maturity
- High degree of initiative, dependability, and ability to work with little supervision while being resilient to change
- Excellent written and verbal communication skills, interpersonal and collaborative skills
- Must be a critical thinker, with strong problem-solving skills
Desired Qualifications
- Deep experience and knowledge of emerging 3GPP security requirements (e.g., 4G, 5G, etc.), ITU-T x.805, ISO27001, NIST, MITRE ATT&CK framework, and related standards
- Knowledge on Telecom communications technologies (Core and/or RAN), security protocols, 3GPP security requirements, ITU-T x.805, ISO27001, NIST, and related standards
- Professional security management certifications are highly desirable, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), and any SIEM related certification (e.g., Splunk or Q-Radar or Logrhythm or leading SIEM(s)) certification
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.