Job Description
Core Responsibilities:
- Continuous Monitoring & Alert Triage: Actively monitor and analyze security events, network traffic, and alerts generated by the SIEM (Security Information and Event Management) platform and other security tools in a 24x7 environment
- Incident Qualification: Perform initial investigation and analysis to determine if an alert is a true positive incident or a false positive; promptly escalating validated security incidents to senior analysts (Tier 2)
- Initial Containment & Response: Execute documented procedures for immediate actions such as network traffic isolation or account disabling
- Log and Traffic Analysis: Conduct analysis of security logs, network packet captures, and endpoint data to establish initial scope and indicators of compromise
- Vulnerability Support: Assist in performing scheduled vulnerability scans, compiling the raw results, and supporting remediation tracking efforts
- Documentation & Reporting: Create clear, detailed incident reports, providing a timeline of events, initial findings, and recommended next steps for further investigation
- Process Adherence: Ensure all incident detection and classification services strictly adhere to established procedures and customer-defined Service Level Agreements (SLAs)
- Threat Intelligence: Continuously research emerging threats (TTPs, IOCs, etc.) and assist in updating internal detection and hunting capabilities
- Operational Excellence: Actively identify opportunities for the automation of routine tasks and improvements in SOC workflow efficiency
- Collaboration: Effectively communicate security issues and investigation findings to customers and internal teams, both verbally and in writing
- Work within a 24x7x365 Security Operations Center, supporting a rotating shift schedule to ensure continuous coverage for multiple customers
- 2-4 years of experience in an operational technology environment, a related internship, or relevant education
- Foundational knowledge of core networking principles (TCP/IP, DNS, HTTP) and general system architecture (Windows/Linux)
- Exposure to or direct experience with security monitoring platforms, preferably a SIEM solution
- Solid understanding of the cyber security threat landscape, including common attack types and vectors (e.g., phishing, malware)
- Demonstrated analytical, problem-solving, and critical thinking skills with the ability to process large amounts of data
- Strong verbal and written communication skills for documentation and professional interaction with clients and peers
Looking to get Placed? Try our Placement Guarantee Plan
- Relevant industry certification such as CompTIA Security+, CompTIA CySA+, or Microsoft SC-200
- Experience with scripting languages (e.g., Python, PowerShell) for task automation
- Academic background (degree or coursework) in Computer Science, Cyber Security, or a related field
- Familiarity with various security management tools (e.g., vulnerability scanners, EDR, firewalls)
- Proven ability to work effectively under pressure and rapidly changing priorities
Skills
PythonLinuxScripting LanguagesIf an employer asks you to pay any kind of fee, please notify us immediately. Jobaaj does not charge any fee from the applicants and we do not allow other companies also to do so.
Important dates & deadlines?
Application Deadline
16 Aug 26, 03:22 PM IST
Similar Jobs
View All

