Posted:9 hours ago| Platform: Foundit logo

Apply

Work Mode

On-site

Job Type

Full Time

Job Description

Lead

Roles and Responsibilities:

  • Serve as the Subject Matter Expert (SME) on SOAR for implementation, playbook creation, and platform management.
  • Address any technical questions from clients and drive the implementation and operations BAUs (Business As Usual) for SOAR.
  • Take end-to-end responsibility to manage/resolve L3 level incidents, customer concerns, and SOC operations for customers.
  • Take full accountability for incidents related to SOAR and pertaining to SOC operations.
  • Work on documentation of Standard Operating Procedures (SOPs) and Root Cause Analyses (RCAs).
  • Act as a coach and mentor to junior Operations/Implementation Engineers and Technicians.
  • Coordinate with Specialists/Sr. Specialists to resolve complex problems.
  • Take ownership of at least two technologies according to domain or specialization.
  • Support Specialists/Sr. Specialists in the effective execution of projects.
  • Perform skills gap analysis and upskill team members wherever needed.
  • Maintain strong relationships with all project stakeholders.
  • Be the immediate contact person for the client.
  • Create and maintain SOP documents.
  • Deliver technical tasks of complex nature as per assigned timelines.
  • Maintain activity logs, SLA details, and other critical information necessary for the smoother execution of projects.
  • Resolve all technical issues/queries which are assigned/escalated.
  • Partner with other cross-functional teams and client teams to provide effective resolution.
  • Guide and share information with other analysts and teams.
  • Develop use cases, content, playbooks, and automation with APIs.
  • Drive automation of all L1 & L2 activities.
  • Serve as the single point of contact to the client stakeholders.
  • Improvise threat hunting capabilities of the technology using automation.
  • Drive continuous development of analytical, statistical, mathematical models leveraging AI/ML capabilities of the technology to enhance threat detection and prediction, and implement advanced use cases.
  • Conduct continuous fine-tuning of configuration, rules, and policies.
  • Drive continuous innovation and automations in intuitive dashboards, reports, and queries.
  • Optimize response time to fetch data and logs in advanced queries, reports, and dashboards.
  • Provide on-the-job training to the client and the team.
  • Participate in client meetings, discussions, etc.
  • Interface with senior management.
  • Establish communications with appropriate team members and business units, providing status updates.
  • Manage reporting, tracking, monitoring, and closing out incident response issues with proper RCA.
  • Interact with internal business units to address incidents and support investigations.
  • Be the focal point for critical security events and incidents, serving as an SME while providing recommendations and guidance to the respective business units and to the SOC lead for escalation and remediation.
  • Handle, respond to, and document all events or incidents that require escalation from Level 2 or Level 1 analysts.
  • Lead efforts in monitoring, reporting, and responding to information security incidents.
  • Recommend controls and process improvements based upon external threat indicators, industry trends, and lessons learned.
  • Be responsible for facilitating incident management team exercises and events.

Skills Requirement:

  • Deep knowledge of

    SOAR (Security Orchestration, Automation, and Response)

    for implementation, playbook creation, and platform management.
  • Proficiency in

    Python

    for SOAR-related tasks.
  • Experience in managing/resolving L3 level incidents.
  • Strong accountability for incidents related to SOAR and SOC operations.
  • Good knowledge of IOAs, Incident Response processes, and Playbooks.
  • Experience in scripting is a plus.
  • Proven ability to coach and mentor junior Operations/Implementation Engineers and Technicians.
  • Experience in coordinating with Specialists/Sr. Specialists to resolve complex problems.
  • Ability to take ownership of at least two technologies according to domain or specialization.
  • Strong relationship management skills with project stakeholders.
  • Experience in creating and maintaining SOP documents.
  • Ability to deliver complex technical tasks within timelines.
  • Proficiency in maintaining activity logs, SLA details, and other critical project information.
  • Experience in resolving technical issues/queries, assigned or escalated.
  • Ability to partner with other cross-functional and client teams for effective resolution.
  • Experience in guiding and sharing information with other analysts and teams.
  • Strong skills in use case creation, content development, playbook creation, and automation with APIs.
  • Experience in automating L1 & L2 activities.
  • Ability to improvise threat hunting capabilities using automation.
  • Experience in continuous development of analytical, statistical, mathematical models leveraging AI/ML capabilities for threat detection and prediction.
  • Experience in continuous fine-tuning of configuration, rules, and policies.
  • Proven ability to drive continuous innovation and automations in intuitive dashboards, reports, and queries.
  • Experience in optimizing response time to fetch data and logs in advanced queries, reports, and dashboards.
  • Ability to provide on-the-job training to clients and the team.
  • Strong communication and interpersonal skills for client meetings and senior management interfacing.
  • Experience in establishing communications with appropriate team members and business units, providing status updates, and reporting/tracking incident response issues with proper RCA.
  • Proven ability to lead efforts in monitoring, reporting, and responding to information security incidents.
  • Experience in facilitating incident management team exercises and events.

QUALIFICATION:

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now
Inspira Enterprise India logo
Inspira Enterprise India

Information Technology & Services

Mumbai

RecommendedJobs for You

Chennai, Tamil Nadu, India

Madurai, Tamil Nadu, India

Thane, Maharashtra, India

Madurai, Tiruppur, Salem, Chennai, Tiruchirapalli, Coimbatore

Kolkata, West Bengal, India