Tata Communications Redefines Connectivity with Innovation and IntelligenceDriving the next level of intelligence powered by Cloud, Mobility, Internet of Things, Collaboration, Security, Media services and Network services, we at Tata Communications are envisaging a New World of Communications
Responsible for 24x7 monitoring of SIEM alerts and security events, performing initial alert triage, identifying potential security incidents, and escalating confirmed or suspicious events to L2/L3 teams within defined SLAs.
Key Responsibilities
- Monitor SIEM dashboards, alerts, events and security incidents on a 24x7 basis.
- Perform L1 alert triage and validate security events.
- Analyze logs from Firewall, WAF, Proxy, EDR, Windows/Linux, AD, DNS, VPN, Email Security and other security devices.
- Identify True Positive (TP) and False Positive (FP) alerts.
- Perform initial investigation of suspicious IPs, domains, URLs, hashes, users and hosts.
- Correlate events from multiple log sources to identify potential threats.
- Escalate confirmed/suspicious incidents to L2/L3 as per the defined escalation matrix.
- Create and update tickets with complete investigation details and evidence.
- Ensure alerts and incidents are handled within defined SLA/KPI timelines.
- Maintain proper shift handover and communicate all pending/high-priority incidents.
- Follow documented SOPs, playbooks and escalation procedures.
- Support daily SOC reports, incident reports and shift reports.
- Monitor SIEM health, log source connectivity and report ingestion issues to the respective teams.
- Participate in incident response, vulnerability-related investigations and security investigations as required.
- Maintain confidentiality and follow organizational security policies.