L3 SOC Analyst

3 weeks ago


bangalore, India CGI Full time

Position Description:

The Level 3 (L3) SOC Analyst is a core resource on the Security Monitoring team (Blue Team) which operates within
CGI’s Global Security Operations Center (GSOC).
As a member of the Security Monitoring team, the L3 Analyst is responsible for the monitoring, triage and response
of all security alerts coming from SIEM and the security controls directly.
The L3 Analyst will have a broad range of cybersecurity experience and skillsets including knowledge of Windows
and Linux operating systems, knowledge of common threats and attack methodologies, an awareness of industry
standards, and foundational endpoint and network-based analysis techniques.

Your future duties and responsibilities:

Continue the investigation of alerts that have been escalated by L2 Analysts within agreed upon SLA's.
Perform triage of indicators, as needed, and document all findings in the appropriate threat knowledgebase.
Perform In-depth analysis of alerts, outside of Standard Operating Procedures, utilizing intermediate endpoint
and network-based analysis techniques.
Make technical and procedural enhancement recommendations in coordination with other members of the team
to improve the overall capabilities and maturity of the SOC.
Create security incidents from presumed true-positive alerts; and close presumed false-positive alerts.
Support Incident Management (IM) when further investigation is required.
Be a subject matter expert of industry trends, new threats, technologies and common security standards and
frameworks.
Engage and collaborate with other members of the GSOC, as well as internal CGI teams, during the investigation
of alerts.
Report security vulnerabilities identified during BAU activities and provide recommendations to mitigate the
overall security risk to the organization.
Create, review, and enhance Standard Operating Procedure (SOP) documentation.
Utilize and contribute to internal threat intelligence.
Perform handover of priority items at the end of shift.
Review alert queues to identify patterns that may indicate broader security issues by taking a "long-term" view of event analysis (weeks and months)
KEY SKILLS & COMPETENCIES
Ability to communicate clearly and effectively in both verbal and written form.
Ability to think critically when investigating alerts to determine appropriate relevance of the alert details.
Ability to methodically research unknown information; including being able to search for information, take notes, and manage time.
Skilled in time management to ensure that all assigned tasks are completed within requested timeframes.
Knowledge of various networking concepts and the ability to utilize that knowledge during an investigation.
Common concepts include IP Address subnets, Network Address Translation (NAT), and the knowledge of
different protocols and ports.
Knowledge of Windows system administration and Event ID's, including knowing the event ID of common events such as logins, login failures, and process creations.
Knowledge of the Linux operating system including common log storage paths, and common Linux commands.
Knowledge of vulnerability management concepts, as well as Common Vulnerabilities and Exposures (CVE).
Ability to analyze log files utilizing advanced tools and techniques.
Knowledge of network security monitoring techniques.
Advanced knowledge of common threats and vulnerabilities, attack methodologies, threat actors, and attack tools.
Awareness of industry standards and frameworks.
Knowledge of IT Service Management (ITSM) with a focus on Incident Management.
Knowledge of foundational open-source intelligence techniques.
Knowledge of any scripting or programming language.
Knowledge of intermediate or advanced threat hunting techniques.
Experience with mentoring more junior analysts.
Knowledge of malware analysis techniques is an asset.
Knowledge of reverse engineering techniques is an asset.

Required qualifications to be successful in this role:

2+ year degree of diploma with a focus on Information Security or Cybersecurity is an asset, but not required.
Advanced Certifications in Information Security or Cybersecurity related disciplines (e.g., CISSP, CCSP, GSEC,
GSOC, GCIA, GMON, GCDA, GCIH, GCFA, GREM, GNFA).
EXPERIENCE
At least, 3 years of experience working in a Security Operations Center as a SOC Analyst, or similar role.
Experience handling alerts from SIEM and common security controls including Network and Host-based IPS and IDS, Endpoint Security, Firewall, and Cloud security.
Experience using use third-party security intelligence tools, such as Virus Total, to safely triage indicators.
Experience performing alert investigation utilizing advanced digital forensics techniques.
Experience supporting or performing incident response activities.
· Experience producing security reports.

Skills:

Cyber
  • Sr Analyst

    3 weeks ago


    Bangalore Metropolitan Area, India Tyson Foods India Full time

    Experience - Min of 6 - 10+yrs of relevant experience in SOC / IRSkills RequiredShould have worked in SOC L3 and L2 teams in prior experienceMust have handled various SIEM and SOAR Tools.Analyzing logs to identify patterns, trends, or other meaningful insights in order to make recommendations for improvementMust have experience handling SNOW ticketing...

  • L3 SOC Manager

    4 weeks ago


    Bangalore, India VIDPRO CONSULTANCY SERVICES Full time

    About the job:We are looking for a highly experienced information security professional to help leading one of the clusters of Synergistic Security Operation Center to monitor security alerts, respond and remediate detected issues, and work with the Incident Management process to remove threats and vulnerabilities within the organization and to assist the...

  • SOC Analyst

    1 week ago


    bangalore, India Resillion Full time

    Job DescriptionSOC Analyst  Experience Range: 2 - 4 Years  Location: Bangalore Key responsibilities Operate within a fast-paced 24x7 SOC environment, either as part of a team or independently, to Analyse alerts and log data promptly and effectively. Assess the severity and impact of potential threats to accurately prioritize alerts and incidents....

  • SOC Analyst

    6 days ago


    bangalore, India [24]7.ai Full time

    SOC Analyst - 1: POSITION SUMMARY : The Level One SOC Monitoring analyst will fit into a global team providing 24/7 monitoring and first line of response for incidents, as L1 Engineer you are expected to conduct investigations, monitor for alerts, triage, and mitigation of detected threats/issues, also to start and track security...


  • bangalore, India Netlabs Global IT Services Pvt Ltd Full time

    Job Responsibilities: Perform monitoring, identification, investigation, documentation, resolution, and reporting of security alerts through prioritization of events based on risk/exposure. Analyze Endpoint Detection and Response (EDR), Network, Cloud and other traffic and log data for potential threats or vulnerabilities. Generating tickets and incident...

  • Embedded Engineer

    3 weeks ago


    Bangalore, Karnataka, India Cientra Techsolutions Full time

    Job Description :- Systems/ Platform Integration/ Firmware Development Engineer- 5 to 8 years of development work experience in networking, security & wireless software solutions for embedded systems. - Design, develop and test high-performance network and wireless solutions on a various SoCs on OpenWRT platforms.Areas of expertize :- Linux Kernel,...

  • Embedded Engineer

    4 weeks ago


    Bangalore, India Cientra Techsolutions Full time

    Job Description : - Systems/ Platform Integration/ Firmware Development Engineer- 5 to 8 years of development work experience in networking, security & wireless software solutions for embedded systems. - Design, develop and test high-performance network and wireless solutions on a various SoCs on OpenWRT platforms.Areas of expertize :- Linux Kernel,...


  • Bangalore, India Manpower Group Full time

    Roles :Looking for Experience in IBM QRadar- Experience in Sophos EDR/XDR- Experience in Ironscale Phising solutions- l2 l3 soc - Utilize IBM QRadar to monitor, investigate, and respond to security incidents. - Configure and tune QRadar rules and policies to ensure accurate and timely detection of threats. - Implement and manage Sophos EDR/XDR solutions to...

  • SOC Analyst

    1 week ago


    bangalore, India MAYNOR CONSULTING Full time

    Responsibilities : Incident Detection and Response : - Monitor security alerts and events to identify potential security incidents.- Investigate and analyze security alerts, incidents, and anomalies.- Provide timely and effective response to identified security incidents.Security Event Analysis : - Conduct in-depth analysis of security events using various...


  • bangalore, India Société Générale Assurances Full time

    Cyber security Senior Analyst ( SOC Cyber defence ) Permanent contract|Bangalore|Innovation / Project / Organization Cyber security Senior Analyst ( SOC Cyber defence ) Bangalore, India Permanent contract Innovation / Project / Organization Responsibilities RESG/GTS is the entity in charge of the entire IT...


  • bangalore, India Société Générale Assurances Full time

    Cyber security Senior Analyst ( SOC Cyber defense ) - L2 Permanent contract|Bangalore|Innovation / Project / Organization Cyber security Senior Analyst ( SOC Cyber defense ) - L2 Bangalore, India Permanent contract Innovation / Project / Organization Responsibilities RESG/GTS is the entity in charge of the entire IT...

  • SOC Analyst

    2 weeks ago


    Bangalore/Jaipur, IN MAYNOR CONSULTING Full time

    Responsibilities : Incident Detection and Response : - Monitor security alerts and events to identify potential security incidents.- Investigate and analyze security alerts, incidents, and anomalies.- Provide timely and effective response to identified security incidents.Security Event Analysis : - Conduct in-depth analysis of security events using various...

  • SOC Analyst

    2 weeks ago


    Bangalore/Jaipur, India MAYNOR CONSULTING Full time

    Responsibilities : Incident Detection and Response : - Monitor security alerts and events to identify potential security incidents.- Investigate and analyze security alerts, incidents, and anomalies.- Provide timely and effective response to identified security incidents.Security Event Analysis : - Conduct in-depth analysis of security events using various...

  • Infosec Manager

    6 days ago


    bangalore, India ZEISS India Full time

    CARL ZEISSCarl Zeiss AG branded as ZEISS, is a German manufacturer of optical systems and optoelectronics, founded in Jena, Germany in 1846 by optician Carl Zeiss.ZEISS is headquartered in Oberkochen, Germany and enjoys a global presence and rich heritage of being in business for more than 170 years.ZEISS today operates in the following businesses:•...

  • Infosec Manager

    6 days ago


    bangalore, India ZEISS India Full time

    CARL ZEISS Carl Zeiss AG branded as ZEISS, is a German manufacturer of optical systems and optoelectronics, founded in Jena, Germany in 1846 by optician Carl Zeiss. ZEISS is headquartered in Oberkochen, Germany and enjoys a global presence and rich heritage of being in business for more than 170 years. ZEISS today operates in the following businesses: •...

  • Infosec Manager

    6 days ago


    bangalore, India ZEISS India Full time

    CARL ZEISS Carl Zeiss AG branded as ZEISS, is a German manufacturer of optical systems and optoelectronics, founded in Jena, Germany in 1846 by optician Carl Zeiss. ZEISS is headquartered in Oberkochen, Germany and enjoys a global presence and rich heritage of being in business for more than 170 years. ZEISS today operates in the following businesses: •...


  • Bangalore, India LKQ India Private Limited Full time

    Excellent Opportunity with LKQ India (Fortune 500 Company & Nasdaq Listed) at Bangalore location. Experience: 6 to 11 YearsWork Location: Bannerghatta Rd, BangaloreRole:: PermanentJob Description: Configure and Administer Splunk SIEM (Security Incident and Event Management) tool. Administer Email Gateway technologies (Microsoft Defender /Abnormal Security)....


  • Hyderabad/Bangalore, India Coretek Labs India Pvt Ltd Full time

    Job Description : - Technical requirements (applies to both roles) :- Effective technical stakeholder's management- Experience in mentoring and training junior analyst- Presentation and Process development- Excellent written and verbal communication skills- Report creation and project skillsSOC Analyst (Tier 3) - 4+year's experience within a...

  • Lead SOC Engineer

    4 hours ago


    bangalore, India Resillion Full time

    Job DescriptionTitle: SOC Engineering Team Lead Experience Range: 10-15 Years  Location: Bangalore About You: The successful candidate will be a passionate information security professional with the ability to communicate to different business and IT leaders. The candidate will demonstrate drive, intelligence, maturity, and energy and will have a proven...


  • bangalore, India 5100 Kyndryl Solutions Private Limited Full time

    Who We Are At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward – always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities. The...