Associate, Cybersecurity Mdr
2 days ago
Ankura is a team of excellence founded on innovation and growth.
- Location: Conditional Remote / Gurgaon
- Hours: 40 hours a week
- Reporting: Director - Threat Detection Operations (TDO)
- Duties include continuous monitoring of Security Information Event Management (SIEM), EDR, XDR, DLP and related platforms for correlated events and alerts and working with the client to take action. Analysts leverage events to determine the impact, document possible causes, and provide useful information to clients.
- A deep understanding of various commercial and open-source network sensors, intrusion detection systems, and event log correlation engines is required as analysts are expected to deliver enhanced threat awareness and knowledge through research and continuous improvement of use cases, signatures, and metrics.
- Knowledgeable in various IR response commands related to Windows, Linux and advanced attack techniques related to Endpoints and servers
- Analysts are also expected to maintain open communication and visibility with their team members, Senior Analysts, Directors, and Clients.
- Usually, employees will be permitted to work remotely in the current operational setup however that setup may change based on company and/or business needs, with or without notice. It may also be considered a conditional privilege as the employees are personally responsible to maintain uninterrupted availability and communication via all official channels throughout their designated shifts. If the employee's performance cannot be satisfactorily ascertained by their manager or the employee is unable to adapt to work without disturbance, they may be called upon to work out of the company’s office.
CAPABILITIES
- Preferred to have some formal training or experience in delivering Managed Security or Managed Detection and Response Services.
- Preferred to have a sound understanding and up-to-date knowledge of common security threats, attack vectors, vulnerabilities, exploits, and Network Architecture / Protocols (such as OSI, TCP/IP, P2P, etc.) and Packet Analysis.
- Must have hands-on experience to correlate and analyze information, raw logs, and complex data sets from a wide variety of enterprise technologies including but not limited to SIEM, UEBA, EDR, IDS, IPS, Proxy, Firewall, DLP, and other Threat intelligence tools and Telemetries for anomalous activity and items of interest.
- Preferred to have the necessary experience to conduct initial triage of security events and incidents; determine the priority, criticality, and impact; facilitate communication within the SOC, escalate to the client for containment and remediation, and document/journal progress throughout the Incident Response Lifecycle within the respective service level objectives.
- Experience in conducting research analysis and data gathering requirements to present in a report format is preferred.
- Should be able to develop/follow standard processes and complete documentation as needed.
- Should be detail-oriented and able to work independently and communicate effectively both verbally and in writing. - Must be flexible enough to work in a 24x7 rotational shift setup, including overnight, weekend, and national holidays.
TECHNICAL
- Traditional SIEM ArcSight ESM.
- Emerging SIEM such as MS Azure Sentinel, Exabeam, Obsidian.
- Experience in handling investigations related to XDR and Good knowledge of latest endpoint/Server based attacks
- Endpoint awareness for Carbon Black, CrowdStrike, SentinelOne, MS Defender.
- Knowledge of IR process, Ticketing tools
- Understanding of KQL, Lucene, Python, and/or other similar programming/query/scripting languages
EDUCATION, TRAINING & CERTIFICATIONS:
- Minimum Experince in SOC/IR 1 yrs plus
- Preferred to have a degree in CS/IT or a Masters's Diploma in the field of IT Security from specialized schools
- Preferred to have relevant entry-level or mid-level security certifications such as CEH, Security+.
COMMUNICATION
- Ability to communicate complex ideas effectively, both verbally and in writing in English and the local office language(s)
- Able to provide reports showing progress or achievement of assigned goals and responsibilities as required.
- Must be an active listener and ask questions of others when clarity is needed
- Demonstrates proactive engagement in meetings and process discussions
KEY PERFORMANCE INDICATORS
- Analyze client networks for threats using analytical platforms for event monitoring such as NSM, SIEM, UEBA, ETDR.
- Deliver client reports based on analyses that are timely, high quality, and accurate.
- Understand and support incident response and triage
- Improve reporting to avoid ‘analysis paralysis’.
- Develop new skills within analytical platforms
INDIVIDUAL & TEAMWORK
- Must be able to effortlessly switch between independent and team-based work
- Understands that the work product is dependent on team efforts and remains responsive to internal and external deadlines
- Able to share ex
-
Gurugram, Haryana, India Ankura Full timeAnkura is a team of excellence founded on innovation and growth. Join Ankura's rapidly growing cybersecurity practice and become a key player in protecting our clients from the ever-evolving threat landscape. Practice Overview: Our diverse team is comprised of seasoned security veterans, including professionals from the intelligence community and leading...
-
Coralogix - Technical Lead (SRC)
3 months ago
Gurugram, India Nexthire Full timeTechnical Lead -SRC ( Security Operations ) Gurgaon, India · Full-time · Senior About The Position Snowbit is a cybersecurity technology innovator with a vision to empower organizations worldwide to address omnipresent cyber risks quickly, efficiently, and cost-effectively. Leveraging years of Israeli cybersecurity...
-
Associate Instrumentation
6 months ago
Gurugram, Haryana, India McDermott Full time**Company Overview**: People power our future. That is why advancing a dynamic, inclusive environment, where everyone grows and thrives is critically important to us. Our ingenuity fuels daily life. Together, we’ve forged some of the most trusted partnerships across the energy value chain to make what was once just an idea a reality: laying subsea...
-
Cloud Security Engineer
2 weeks ago
Gurugram, India NEXTHIRE LLP Full timeTechnical Lead -SRC ( Security Operations )Gurgaon, India - Full-time - SeniorAbout The Position :Snowbit is a cybersecurity technology innovator with a vision to empower organizations worldwide to address omnipresent cyber risks quickly, efficiently, and cost-effectively. Leveraging years of Israeli cybersecurity expertise, Snowbit offers Paranoid!, the...
-
Post Market Surveillance Trainee
2 months ago
Gurugram, Haryana, India BAXTER Full timeVantive: A New Company Built on Our Legacy Since last year, Baxter has been on a journey to separate our Kidney Care segment into a standalone company. Vantive* will build on our nearly 70-year legacy in acute therapies and home and in-center dialysis to provide best-in-class care to the people we serve. We believe Vantive will not only build our leadership...
-
Post Market Surveillance Trainee
5 months ago
Gurugram, Haryana, India BAXTER Full time**Vantive: A New Company Built On Our Legacy** Baxter is on a journey to separate our ~$5B Kidney Care segment into a standalone company. Vantive* will build on our nearly 70-year legacy in acute therapies and home and in-center dialysis to provide best-in-class care to the people we serve. We believe Vantive will not only build our leadership in the kidney...
-
Electrical Designer
6 months ago
Gurugram, Haryana, India McDermott Full time**Job Overview**: The Electrical Designer provides solutions to problems in the Electrical Design discipline without supervisory approval and will evaluate and select solutions from established operating procedures and/or scientific procedures. **Key Tasks and Responsibilities**: - Prepare and develop arrangement and detail FEED, studies, and detail design...
-
Senior Cloud Security Analyst
1 month ago
gurugram, India Coralogix Full timeAbout The PositionSnowbit is a cybersecurity technology innovator with a vision to empower organizations across the globe to quickly, efficiently, and cost-effectively ready themselves to address omnipresent cyber risk. Built off years of Israeli cybersecurity experience, Snowbit is looking to offer the broadest managed detection and response offering...
-
Cyber Security Sales Associate
2 weeks ago
Haryana, India Xiarch Solutions Pvt Ltd Full timeAbout Xiarch Solutions Pvt LtdXiarch is a decade-old company founded by the alumni of IVY league universities. It is a CERT-IN empaneled & ISO 9001-2015, 27001-2013 certified Global Consulting firm and is an acronym for Xtreme InfoSec Auditors, Researchers, Consultants, and Hackers.Headquartered in Gurgaon, we have our delivery centers at Gurugram (Haryana),...
-
Associate, Cybersecurity Incident Response
6 months ago
Gurugram, Haryana, India Ankura Full timeAnkura is a team of excellence founded on innovation and growth. - Practice Overview: - Our diverse team is comprised of seasoned security veterans, including professionals from the intelligence community and leading private security firms, alongside talented early-career professionals. This unique blend of experience and fresh perspectives allows us to...
-
EDR Security Analyst
1 month ago
gurugram, India Soffit Infrastructure Services (P) Ltd Full timeJob Overview: The EDR Specialist will be responsible for supporting the deployment and operational effectiveness of endpoint security solutions, including EDR/MDR, antivirus, threat hunting, and forensics tools. This role requires close collaboration with the user department and other technical teams to ensure that security measures are in place to detect,...
-
Intern Inside Sales Associate
2 months ago
Jharsa, Gurugram, Haryana, India Reticen8 Technologies Pvt Ltd Full time**Job description** **Job description** **Job Description: Intern Inside Sales Associate (3 Openings)** **Location**: Gurgaon, Haryana, India **Company**: Reticen8 Technologies Private Limited **Working Hours**: 9:30 AM to 7:00 PM, 5 Days a Week **Position Overview**: **Stipend and Compensation**: - **First 3 Months (Internship Period)**: INR 8,000 per...
-
Senior Cloud Security Analyst
6 months ago
Gurugram, India Coralogix Full timeAbout The PositionSnowbit is a cybersecurity technology innovator with a vision to empower organizations across the globe to quickly, efficiently, and cost-effectively ready themselves to address omnipresent cyber risk. Built off years of Israeli cybersecurity experience, Snowbit is looking to offer the broadest managed detection and response offering...
-
Senior Cloud Security Analyst
6 months ago
Gurugram, India Coralogix Full timeAbout The Position Snowbit is a cybersecurity technology innovator with a vision to empower organizations across the globe to quickly, efficiently, and cost-effectively ready themselves to address omnipresent cyber risk. Built off years of Israeli cybersecurity experience, Snowbit is looking to offer the broadest managed detection and response offering...
-
Senior Cloud Security Analyst
2 months ago
gurugram, India Coralogix Full timeAbout The PositionSnowbit is a cybersecurity technology innovator with a vision to empower organizations across the globe to quickly, efficiently, and cost-effectively ready themselves to address omnipresent cyber risk. Built off years of Israeli cybersecurity experience, Snowbit is looking to offer the broadest managed detection and response offering...
-
Senior Cloud Security Analyst
1 month ago
gurugram, India Coralogix Full timeAbout The Position Snowbit is a cybersecurity technology innovator with a vision to empower organizations across the globe to quickly, efficiently, and cost-effectively ready themselves to address omnipresent cyber risk. Built off years of Israeli cybersecurity experience, Snowbit is looking to offer the broadest managed detection and response offering...
-
Senior Cloud Security Analyst
6 months ago
Gurugram, India Coralogix Full timeAbout The PositionSnowbit is a cybersecurity technology innovator with a vision to empower organizations across the globe to quickly, efficiently, and cost-effectively ready themselves to address omnipresent cyber risk. Built off years of Israeli cybersecurity experience, Snowbit is looking to offer the broadest managed detection and response offering...
-
IT Support- Associate
2 months ago
Gurugram, Haryana, India Arbolus Technologies Full time**About Arbolus** Arbolus is reinventing the traditional and analog expert network industry by bringing technology to the forefront of knowledge sharing. Our platform helps hundreds of clients worldwide to connect with the best experts, collect high-quality insights faster, and streamline their processes using leading AI technology. Headquartered in...
-
Civil/structural Designer
5 months ago
Gurugram, Haryana, India McDermott Full time**Job Overview**: The Civil/Structural Designer provides solutions to problems in the Civil/Structural Design discipline without supervisory approval and will evaluate and select solutions from established operating procedures and/or scientific procedures. **Key Tasks and Responsibilities**: - Prepare and develop arrangement and detail design drawings of...
-
Cyber Security Research Associate
5 months ago
Gurugram, Haryana, India Ramognee Technologies Pvt. Ltd. Full timeJob Purpose: As a research associate this role would be focused on research with the goal to enhance the existing product capabilities or work on topics to create new technologies. Basic - Individual Contributor and would be part of the Security team of the organization and work directly with the senior management. Job Duties: Supports the organization and...