Senior SOC Analyst (Level 3)
Bangalore/Gurgaon, IndiaAXA XL has an exciting opportunity for an experienced L3 Senior SOC analyst to join the Security Operations team, supporting security incident investigations across the organisations global infrastructure and responding to escalations from the Level 1 and 2 SOC teams. The successful candidate will have a history of successfully managing complex and high-severity cyber security incidents.DISCOVER your opportunityWhat will your essential responsibilities include?xc2xb7 Take full ownership of incidents escalated by Level 2 analysts.xc2xb7 Conduct complex investigations and provide advice to L2 SOC analysts.xc2xb7 Develop customized scripts and procedures to automate repetitive tasks and improve the efficiency of incident response activities.xc2xb7 Provide expert advice on incident remediation and recovery efforts.xc2xb7 Develop threat remediation strategies.xc2xb7 Perform proactive analysis of AXA XLs attack surface and advice on potential threats and attack vectors.xc2xb7 Review and provide feedback on security control capability gaps based on security intrusion trends.xc2xb7 Create and refine runbooks/playbooks for all alerts.xc2xb7 On-board log sources and work on log issues.xc2xb7 Fine-tune EDR and other tooling to exclude noise and false positives.xc2xb7 Create and fine-tune content in SIEM - correlation rules, Dashboard and Reports.xc2xb7 Interact with SIEM, EDR and other SOC tooling vendors (TAC Support) to remediate any issues with tooling.xc2xb7 Monitor API threat detection, reporting and containments.xc2xb7 Demonstrate experience in conducting digital forensics investigations relating to incident detection and response.xc2xb7 Responsible for making decisions and identifying required actions. During high-severity security incidents, you will advise the AXA XL Head of SOC, CISO and CSO on appropriate containment, eradication, and remediation measures.xc2xb7 Provide an after-hours point of escalation for critical incidents.xc2xb7 Define the operational roadmap and key metrics for incident detection and response.xc2xb7 Collaborate with internal stakeholders to align on and implement security incident detection and response processes.xc2xb7 Develop SOC security incident policies and investigation procedures, for use across multiple information systems and teams.xc2xb7 Conduct compliance monitoring and perform SOC/SIEM security control testing.xc2xb7 Analyze, define, and manage the delivery of new SIEM rules.xc2xb7 Conduct use case testing and modify or create as and when required.xc2xb7 Create new custom detection rules using KQL.xc2xb7 Design and implement SIEM and EDR enhancements and configurations.xc2xb7 Manage and represent the Security Operations team on ethical hack exercises.You will report to the Head of SOC.QualificationsSHARE your talentWe are looking for someone who has these abilities and skills:Required Skills and Abilities:xc2xb7 Good knowledge of Microsoft Defender and Microsoft Sentinel, including developing complex KQL queries.xc2xb7 Experience in performing digital forensics investigations.xc2xb7 Experience in developing scripts (Python, Powershell, etc.) quickly in reaction to incidents.xc2xb7 Demonstrate experience of good knowledge in information security principles applied to architecture, networks & systems, digital forensics, security risk assessments and software development).xc2xb7 Good knowledge and understanding of technologies utilized in cyber security (SIEM, SOAR, Firewalls, IAM, IDS/IPS, Anti-malware, End Point Protection, Database Security, Threat management/intelligence).xc2xb7 Actionable knowledge of MITRE ATT&CK framework.xc2xb7 Effective knowledge of exploitable vulnerabilities and remediation techniques.xc2xb7 Experience in automating manual processes for responding to security incidents.xc2xb7 Experience in threat intelligence and CERT/CSIRT activities.xc2xb7 Knowledge of current threat actor techniques.xc2xb7 Understanding of threat landscapes and threat modelling, security threat and vulnerability management, and security monitoring.xc2xb7 Awareness of tools and techniques used by attackers to enter corporate networks, including common IT system flaws and vulnerabilities.Desired Skills and Abilities:xc2xb7 Excellent troubleshooting and critical thinking skills.xc2xb7 Experience in SOC documentation development.xc2xb7 Demonstrated experience in communicating complex security concepts, both verbally and in writing, to a variety of audiences.xc2xb7 Must take ownership of tasks and demonstrate a high degree of autonomy to ensure completion.xc2xb7 Must be personable and foster good stakeholder and peer group working relationships.xc2xb7 Certifications such as CISSP, GIAC, CEH or other.FIND your futureAXA XL, the P&C and speciality risk division of AXA, is known for solving complex risks. For mid-sized companies, multinationals and even some inspirational individuals we dont just provide re/insurance, we reinvent it.How? By combining a comprehensive and efficient capital platform, data-driven insights, leading technology, and the best talent in an agile and inclusive workspace, empowered to deliver top client service across all our lines of business xe2x88x92 property, casualty, professional, financial lines, and speciality.With an innovative and flexible approach to risk solutions, we partner with those who move the world forward.Learn more atInclusion & DiversityAXA XL is committed to equal employment opportunity and will consider applicants regardless of gender, sexual orientation, age, ethnicity and origins, marital status, religion, disability, or any other protected characteristic.At AXA XL, we know that an inclusive culture and a diverse workforce enable business growth and are critical to our success. Thats why we have made a strategic commitment to attract, develop, advance and retain the most diverse workforce possible, and create an inclusive culture where everyone can bring their full selves to work and reach their highest potential. Its about helping one another xe2x80x94 and our business xe2x80x94 to move forward and succeed.
MNCJobsIndia.com will not be responsible for any payment made to a third-party. All Terms of Use are applicable.