Job Description:
- Proficient in Incident Management and Response
- 4+ years working experience in Information Security field.
- Experience with system administration skill set in both Unix and Windows technologies with Integration of devises such as windows, Unix, linux IDS etc.
- Experince in Installation, trouble shooting and up gradation of connectors.
- Experince in Installation, implementation, troubleshooting of ArcSight
- ESM, Logger, troubleshooting, setup
- Health checks & configuration of rules, reports, dashboards, data monitoring etc.
- Excelled at troubleshooting new and unknown problems with little guidance
- Developed, performance tested, and deployed advanced ArcSight ESM content
- Installed, migrated, and maintaining Stock ArcSight.
- Excellent communication and customer interaction skills
- Advanced technical writing skills.
- Use case creation on ArcSight
Roles and Responsibilities:
- Lead and manage Security Operations Center
- Strong experience in team management and project management.
- Primarily responsible for security event monitoring, management and response
- Ensure incident identification, assessment, quantification, reporting, communication, mitigation and monitoring
- Ensure compliance to SLA, process adherence and process improvisation to achieve operational objectives
- Revise and develop processes to strengthen the current Security Operations Framework, review policies and highlight the challenges in managing SLAs
- Responsible for team & vendor management, overall use of resources and initiation of corrective action where required for Security Operations Center
- Management, administration & maintenance of security devices under the purview of ITRC which consists of state-of-the art technologies
- Perform threat management, threat modeling, identify threat vectors and develop use cases for security monitoring
- Responsible for integration of standard and non-standard logs in SIEM
- Creation of reports, dashboards, metrics for SOC operations and presentation to Sr. VP/Mgmt.
- Co-ordination with stakeholders, build and maintain positive working relationships with them
Educational Qualifications:
- BE-IT / B Tech /Comps
- CEH
- Additionally one more certification in information security domain is additional.
- CISSP
- PMP
- GCIH
- GSEC