Senior SOC Engineer
On-siteChennai, Tamil Nadu, India
Job Summary
Manage the 24/7 Cyber Defence Centre as the first line of defense against malicious events, handling security incidents with rapid response capabilities. Analyze security system logs, tools, and data sources daily to identify attacks, improper access patterns, and event correlations, while developing detection rules and system tuning suggestions. Support the SOC by enhancing tools, designing working practices, and executing crisis communication plans for CXO stakeholders. Research emerging threats to develop profiles and measure performance metrics to communicate security value to business leaders.
Required Qualifications
- Security Incident Response and Handling techniques
- Log management and filtering solutions
- Windows Server-based systems including DNS, DHCP, IIS, NPS, RDS, DFS, Hyper-V
- Cloud platforms (i.e. Azure / AWS)
- VMware and similar virtualization technologies
- Virtualization principles & Technologies
- PKI
- Networking principles
- Working knowledge of compliance standards such as ISO27001, PCI-DSS & Cyber Essentials Plus
- SIEM Tools
- Nessus or other Vulnerability management tool
- Security principles and operations
- Firewall, IDS/IPS configuration
- Email and Web filtering services and configuration
- Manage the Cyber Defence Centre (SOC), which is a 24/7 environment
- Handle security incidents and provide rapid response
- Develop and execute a crisis communication plan for CXO and other stakeholders
- Measures SOC performance metrics and communicates the value of security operations to business leaders
Desired Qualifications
- Bachelor's Degree in computer science with a minimum of 7 years related experience
- Experience working in or with a Security Operations Centre and managing security issues and incidents
- Threat Hunting - Analyses security system logs, security tools, and available data sources on a day-to-day basis to identify attacks against the enterprise and report on any irregularities, issues related to improper access patterns, trending, and event correlations and make suggestions for detection rules and system tuning
- Performs research into emerging threat sources and develops threat profiles. Keep updated on the latest cybersecurity threats
- Has a sound understanding of SIEM, PAM, CASB, EDR, other threat detection platforms, and Incident Response tools
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.