SOC Support Engineer
Nutné:SecuritySenior
As a Systems Specialist, will be providing support in thefollowing areas:
- d) Stay updated with the latest vulnerabilities, securitytrends, and techniques in cyber threats and hacking methodologies.
- e) Conduct research on emerging threats and vulnerabilitiesand provide recommendations for enhancing the organization's security posture.
- f) Conduct proactive threat hunting exercises to identifyand investigate potential security incidents and suspicious activities withinthe network.
- g) Document all findings, analysis, recommendations andinvestigation results in a clear and concise manner and generate reports formanagement and stakeholders.
- h) Develop and tune security monitoring rules, correlationlogic, and detection signatures.
- i) Be proficient in utilizing various security technologies,including SIEM (Security Information and Event Management) tools, networktraffic analysis tools, endpoint detection and response (EDR) systems,vulnerability management system and threat intelligence platforms.
- j) Work closely with other cybersecurity teams, such as forincident response, security operations, and threat intelligence, to sharefindings and collaborate on incident investigations.
- k) Develop and implement a cyber intelligence framework toprovide a systematic and organized framework for collecting, processing, andleveraging intelligence to enhance client's cybersecurity posture anddecision-making capabilities.
- l) Integrate the cyber intelligence framework with theclient's Security Operations Center (SOC) and incident response team and ensurethat the intelligence gathered is effectively used to detect, prevent, andrespond to cyber threats.
- m) Continuously monitor and collect information frommultiple sources, including threat intelligence feeds, security vendors, darkweb forums, social media, and other online platforms, to identify emergingcyber threats and attack trends.
- n) Analyze the collected threat intelligence data toidentify patterns, trends, and potential cybersecurity risks.
- o) Prioritize and triage threats based on their relevanceand potential impact to client.
- p) Conduct in-depth analysis of threat actors, theirmotivations, capabilities, and tactics, and provide insights on potential risksand impacts to the organization's systems, networks, and data.
- q) Produce regular and ad-hoc reports, briefings, and alertson emerging threats, trends, and risk assessments to relevant stakeholders,including senior management, incident response teams, and other cybersecurityteams. The report shall also provide technical information in a clear andactionable format for various stakeholders.
- r) Provide timely and accurate intelligence support duringsecurity incidents, assisting incident response teams in understanding thenature and scope of the threat, and providing guidance on containment,remediation and recovery strategies.
- s) Support vulnerability management efforts by analyzingthreat intelligence data to identify vulnerabilities, exploit trends, andpotential targets, and prioritize patching and mitigation activities.
- t) Collaborate with threat hunters and other cybersecurityteams to develop and refine threat hunting strategies based on threatintelligence insights and analysis.
- e) 24x7 standby support as and when required
Qualifications
- a) Possess fundamental application security knowledge likeinterpretation of HTTP response status codes and WAF violations.
- b) Display understanding of network security best practices.
- c) Display understanding of techniques in cyber threats andhacking methodologies.
- d) Strong problem-solving skills and ability to work underpressure. Willingness to learn.
- e) Fundamental skills on Microsoft Office products like Wordand Excel.
- f) Additional certifications like CCNA, CCNP, CISSP orrelated certifications are a plus.
- g) Must be able to work beyond business hours includingweekend when necessary