Cyber Security Incident Response Analyst

4 weeks ago


Any Location, IN Edstem Technologies Full time

Role : CSIRT Incident Response Analyst.

The Cyber Security Incident Response Team (CSIRT) Member conducts essential cyber security incident handling activities to defend the organization from cyber-attacks, through timely detection, investigation and remediation of potential threats.

- They are the primary contact for any suspected security incident and work together with the SOC team to resolving incidents and remediating threats.

Main tasks and responsibilities :

- Serve as the main local escalation point and work with the IR Team on security incident prioritization and management.

- Responsible for acting on alerts, events, and incidents escalated from the SOC Team.

- Perform technical cyber security investigations on escalated security incidents to validate and. implement (coordinate the implementation of) recommended actions containment /remediation /eradication of threats.

- Perform detailed cyber security investigation on security alerts and escalated security incidents (including vCERT for Critical Incidents) to validate and implement (coordinate the implementation of) recommended actions on containment/remediation/eradication of threats.

- Serve as a Subject Matter Expert (SME) on the incident response & technical investigation. lifecycle utilizing local security tool stack, packet captures, reports, data visualization, and pattern analysis,


- Compile Post Incident Analysis report based on Lessons Learned from critical cybersecurity incidents and work on closing the vulnerability that led to a security incident.


- Serve as a Cyber Security Champion, providing implementation and maintenance of security policies and threat models across an array of local security tool stacks (EDR, NDR, Email protection, etc.).

- Review the vulnerability finding reports and coordinate mitigation activities.

- Providing a 360 view and in-depth analysis of past incidents, owning the deep dive and. coordination to turn data into information.

- Coordinate onboarding/troubleshooting activities with various client teams to ensure high data fidelity and continuous data stream on all Log Sources monitored.

- Gather and continuously update the CFC systems with client contextual information and inventory of onboarded log sources.

- Development of custom reporting to the client from the available CFC data


- Provision customer support through audits.


Qualifications, Experience, Skills :

- Minimum 4 years of security experience and 5 plus years of IT experience preferably Bachelor's.

- Degree in Computer Science, Computer Networking, or Computer Security or equivalent.

- CISSP or CISA or CISM Certifications or equivalent.

- Advanced understanding of information security, border protection, incident handling & response, endpoint protection & encryption.

- Strong understanding of computer science: algorithms, data structures, databases, operating systems, networks, and tool development.

- Able to evaluate current people, processes, technology, and business drivers to improve the SOC service.

- Network infrastructure knowledge, advanced knowledge of TCP/IP and Internet protocols.

- Experience with network packet and Netflow analysis, In-depth knowledge of infrastructure and operating systems.

- Policy and Standards, Incident Management, Prioritization, Technologies, Security, Testing, Monitoring, IT Change, Infrastructure, Application.

- Understanding and experience using various security-related exploits and tools.

- Strong ability to communicate write clearly and speak authoritatively to different audiences.

- Advanced knowledge in; Firewalls, VPN, Intrusion detection and prevention systems, anti-virus
and content filtering, URL filtering, authentication solutions, switches, routers, VoIP, and DMZ.

- Red teaming, VA PT experience is an added advantage.

- Exp is 5 to 10 years.


- Remote

(ref:hirist.tech)

  • Any Location, IN Tekvaly Full time

    Job Description :As a Cyber Security Engineer, you will be responsible for safeguarding our systems and networks against security threats. You will work closely with IT teams to design and implement security protocols, conduct vulnerability assessments, and respond to security incidents. Your expertise in cyber security will be crucial in maintaining the...


  • Any Location, IN Tekvaly Full time

    Job Description :As a Cyber Security Engineer, you will be responsible for safeguarding our systems and networks against security threats. You will work closely with IT teams to design and implement security protocols, conduct vulnerability assessments, and respond to security incidents. Your expertise in cyber security will be crucial in maintaining the...


  • Any Location, IN Zongovita Tech Full time

    Cyber Security EngineerLocation : Bangalore, Karnataka (In-Office Position)About the Role : - We're seeking a Cybersecurity Engineer with expertise in DevSecOps and AWS environments.- You'll integrate security into our development processes and safeguard our cloud infrastructure.Key Responsibilities : - Implement security best practices in CI/CD...


  • Any Location, IN Zongovita Tech Full time

    Cyber Security EngineerLocation : Bangalore, Karnataka (In-Office Position)About the Role : - We're seeking a Cybersecurity Engineer with expertise in DevSecOps and AWS environments.- You'll integrate security into our development processes and safeguard our cloud infrastructure.Key Responsibilities : - Implement security best practices in CI/CD...


  • Any Location/Bangalore, IN Augmentedresourcing Pvt. Ltd. Full time

    Job Description :- Handle escalations from Level L1/L2 Threat Analysts, providing guidance and advice on investigation procedures.- Onboard and train new Threat Analysts to ensure proficiency and alignment with organizational objectives.- Participate actively in Security Operations process improvement initiatives, contributing to the enhancement and creation...


  • Any Location/Bangalore, IN Augmentedresourcing Pvt. Ltd. Full time

    Job Description :- Handle escalations from Level L1/L2 Threat Analysts, providing guidance and advice on investigation procedures.- Onboard and train new Threat Analysts to ensure proficiency and alignment with organizational objectives.- Participate actively in Security Operations process improvement initiatives, contributing to the enhancement and creation...


  • Any Location, IN Blue Silicon Infotech Private Limited Full time

    Experience : 6+ years of experienceJob Overview : We are seeking an experienced Cybersecurity Engineer with a strong emphasis on security in AWS to join our dynamic team. As a Cybersecurity Engineer, you will play a pivotal role in designing and implementing secure, scalable, and high-performance solutions on the AWS platform. The ideal candidate will bring...


  • Any Location, IN Blue Silicon Infotech Private Limited Full time

    Experience : 6+ years of experienceJob Overview : We are seeking an experienced Cybersecurity Engineer with a strong emphasis on security in AWS to join our dynamic team. As a Cybersecurity Engineer, you will play a pivotal role in designing and implementing secure, scalable, and high-performance solutions on the AWS platform. The ideal candidate will bring...


  • Any Location, IN Blue Silicon Infotech Private Limited Full time

    Responsibilities:1. Collaborate with cross-functional teams to understand business requirements and design scalable and secure AWS solutions.2. Architect, design, and implement cloud security solutions to protect sensitive information and ensure compliance with industry standards.4. Provide expertise in identity and access management, encryption, network...


  • Any Location, IN Blue Silicon Infotech Private Limited Full time

    Responsibilities:1. Collaborate with cross-functional teams to understand business requirements and design scalable and secure AWS solutions.2. Architect, design, and implement cloud security solutions to protect sensitive information and ensure compliance with industry standards.4. Provide expertise in identity and access management, encryption, network...


  • Any Location/Noida, IN Optimal Virtual Employee Full time

    About OVE: OVE is a multinational corporation headquartered in Australia, specializing in IT services. Our core focus is to deliver technical support through our skilled experts by deploying them on projects for our diverse global client base. Established in 2008, Optimal Virtual Employee has proudly remained a self-funded company for over 14 years....


  • Any Location, IN HARP Technologies and Services Full time

    Location : Hyderabad (Remote)Shift : EST (6.30 pm IST to 2.30 am IST). Potential to change to morning overlapped hours (Overlap: 1.30 pm IST to 9.30 pm IST)Exp : 4 to 7 yearsResponsibilities :- Lead the Data Loss Prevention (DLP) program implementation- Develop, monitor and maintain DLP endpoints and cloud security policies and procedures to prevent...


  • Any Location, IN HARP Technologies and Services Full time

    Location : Hyderabad (Remote)Shift : EST (6.30 pm IST to 2.30 am IST). Potential to change to morning overlapped hours (Overlap: 1.30 pm IST to 9.30 pm IST)Exp : 4 to 7 yearsResponsibilities :- Lead the Data Loss Prevention (DLP) program implementation- Develop, monitor and maintain DLP endpoints and cloud security policies and procedures to prevent...


  • Any Location/Bangalore/Hyderabad, IN Change leaders Full time

    Job Description :Key roles and responsibilities :- Understand, adapt and learn Customer Security/Cybersecurity processes and requirements- Support Security activities for ISO21434 compliance- Support Security awareness across (customer) departments- Perform Security Management activities during all project phases including Threat Analysis and Risk Assessment...

  • Optimas Technologies

    4 weeks ago


    Any Location/Anywhere in India/Multiple Locations, IN Optimas-AI Full time

    Role : SOC Lead/L3 Mandatory Skills : SOC Monitoring, SOC Operations Management, Incident Management, SIEM, Firewalls, Proxy, Load Balancers, Security Incidents. Team Management1. Security Monitoring : Configuration services, Incident Response services and SIEM Tools 2. Asset Onboarding, Reconciliation based on Customer Requirements and Asset Management.3....

  • Optimas Technologies

    4 weeks ago


    Any Location/Anywhere in India/Multiple Locations, IN Optimas-AI Full time

    Role : SOC Lead/L3 Mandatory Skills : SOC Monitoring, SOC Operations Management, Incident Management, SIEM, Firewalls, Proxy, Load Balancers, Security Incidents. Team Management1. Security Monitoring : Configuration services, Incident Response services and SIEM Tools 2. Asset Onboarding, Reconciliation based on Customer Requirements and Asset Management.3....

  • IT Security Analyst

    2 months ago


    Any Location, IN Info Origin Inc Full time

    Job Description :We are seeking a motivated and security-conscious individual to join our team and play a key role in securing our application landscape. You will be responsible for developing and maintaining system security plans (SSPs) in accordance with industry standards, ensuring our applications comply with security regulations.Responsibilities :-...

  • IT Security Analyst

    4 weeks ago


    Any Location, IN Info Origin Inc Full time

    Job Description :We are seeking a motivated and security-conscious individual to join our team and play a key role in securing our application landscape. You will be responsible for developing and maintaining system security plans (SSPs) in accordance with industry standards, ensuring our applications comply with security regulations.Responsibilities :-...


  • Any Location, IN CallTek Full time

    Job Description :- Prepare a computer with basic configurations of Operative System, Drivers and Network.- Install and configure Office 365 and basic Applications or Software according to Installation Guides.- Identify basic Hardware or Electric Issues (as High CPU and/or RAM consumption or battery damage). Register and control of IT assets assignment :-...

  • Rapid Technologies

    4 weeks ago


    Any Location, IN Rapid Technologies Full time

    Job Description :- Use ITIL-based IT service management processes, including incident and problem management processes, change management, knowledge management, configuration and release management and ensure relevant activities are carried out to minimise unpredicted impact on production services- Participate and contribute to IT governance and reporting...