JOB DESCRIPTION
Actively monitoring, analysing & escalating SIEM alerts based on correlation rules,
Email protection alerts & malware analysis,
Provide inputs for proactive content fine tuning & use case enablement,
Active threat hunting on network flow, user behaviour & threat intelligence,
Phishing email analysis for MFs,
Raising incidents in Pastebin inte
Should be familiar with Domain Knowledge (Cyber Security), Threat Hunting, SIEM- Azure Sentinel, SIEM - (RSA / Splunk / LogRhythm), Python Scripting, Windows Active Directory, Operating systems and servers.
Ability to Triage and assignment Incident Handling.
Ability to Follow Playbooks instructions- Incident Response Playbooks
Ability to Comprehend Logs (HTTP, SMTP, Network) (Under guidance)
Understand and imbibe current SOC process
Perform quality assessment on SOC operations being performed as per existing process
Record and deviations identified into tracking tool(s)/spreadsheets
Perform follow-ups with respective error owners to mitigate process deviations
Identify process deviations, Summarize and generate trends, patterns into process deviations / errors observed.
Perform RCA into observed errors / trends and generate recommendations for process improvement
Generate personnel specific recommendations for performance enhancement
Contribute in overseeing quality assessment process for multiple SOC verticals
In-line alignment with SOC operations for quick-detection / prevention of process deviations
Support as QA touchpoint in critical cyber incidents to enhance quality of service
Assessment of investigation report with assertions, evidences and recommended actions
KPMG India has a policy of providing equal opportunity for all applicants and employees regardless of their color, caste, religion, age, sex/gender, national origin, citizenship, sexual orientation, gender identity or expression, disability or other legally protected status. KPMG India values diversity and we request you to submit the details below to support us in our endeavor for diversity. Providing the below information is voluntary and refusal to submit such information will not be prejudicial to you .