Mumbai Shivaji Park, India
3 days ago
IN_Senior Associate_SOC _Managed Services_Advisory_Mumbai

Line of Service

Advisory

Industry/Sector

FS X-Sector

Specialism

Risk

Management Level

Senior Associate

Job Description & Summary

The SOC Analyst –L3 will be part of existing Ares Global SOC team and will be responsible for day-to-day security operations by responding to and investigating security events of interest and recommending or taking corrective action by working with IT and non-IT team members. They will also respond to security incident and investigation requests in line with established Security Incident Response processes and procedures, within defined service level targets. This position requires shift work in a 24*7*365 environment.

*Why PWC

At PwC, you will be part of a vibrant community of solvers that leads with trust and creates distinctive outcomes for our clients and communities. This purpose-led and values-driven work, powered by technology in an environment that drives innovation, will enable you to make a tangible impact in the real world. We reward your contributions, support your wellbeing, and offer inclusive benefits, flexibility programmes and mentorship that will help you thrive in work and life. Together, we grow, learn, care, collaborate, and create a future of infinite experiences for each other. Learn more about us.

At PwC, we believe in providing equal employment opportunities, without any discrimination on the grounds of gender, ethnic background, age, disability, marital status, sexual orientation, pregnancy, gender identity or expression, religion or other beliefs, perceived differences and status protected by law. We strive to create an environment where each one of our people can bring their true selves and contribute to their personal growth and the firm’s growth. To enable this, we have zero tolerance for any discrimination and harassment based on the above considerations. "

 

Responsibilities:

Detailed Responsibilities/Duties

Responsible for initial or secondary triage of security incidents identified by internal controls or external SOC partnersProficient in Threat Research and understands the latest malware trends, common attack TTPs, and the general threat landscapeProficient in Incident Response and automation workflows as it relates to Security OperationsDemonstrates ability to author content using a variety of query languages, as well as scripting for event enrichment and investigationDetects, identifies, and responds to cyber events, threats, security risks and vulnerabilities in line with cyber security policies and proceduresConducts threat hunting and analysis using various toolsets based on intelligence gatheredResponsible for documenting the incident life cycle, conducting handoffs’, escalation, and providing support during cyber incidentsCreate detailed Incident Reports and contribute to lessons learned in collaboration with the teamWorks with vulnerability management resources to uncover and prioritize potential risks and makes specific recommendations to reduce the threat landscape and minimize riskWorks with leadership and the engineering team to improve and expand available toolsets when warrantedare critical for the role

Required Qualifications
Skills

Experience with one or more Security Information and Event Management (SIEM) solutionsUnderstanding of common Attack methods and their SIEM signaturesExperience in security monitoring, Incident Response (IR), security tools configuration and security remediationStrong knowledge and experience in Security Event Analysis capabilityUnderstanding of network protocols (TCP/IP stack, SSL/TLS, IPSEC, SMTP/IMAP, FTP, HTTP etc.)Understanding of Operating System, Web Server, database, and Security devices (firewall/NIDS/NIPS) logs and log formatsUnderstanding of String Parsing and Regular ExpressionsStrong analytical and problem-solving skillsHigh level of personal integrity, and the ability to professionally handle confidential matters and show an appropriate level of judgment and maturityAbility to interact effectively at all levels with sensitivity to cultural diversityAbility to adapt as the external environment and organization evolvesPassionate about Cybersecurity domain and has the inclination to learn current technologies / concepts / improvementsExcellent in security incident handling, documentation, root cause analysis, troubleshooting and publishing post-Incident Reports.Strong experience with cyber security in the domains of cyber threat intelligence and analysis, security monitoring and incident responseExperience of network and system vulnerabilities, malware, networking protocols and attack methods to exploit vulnerabilitiesKnowledge of cyber security frameworks and attack methodologiesExperience working with EDRs, Proxies, and anti-virusKnowledge of intrusion detection methodologies and techniques for detecting host- and network-based intrusions via intrusion detection technologiesExcellent verbal and written English communication skills

Mandatory skill sets:

Tools

Email Security: Proofpoint, Abnormal Security, M365 DefenderSOAR: Palo Alto XSOARSIEM: SplunkFirewall: Palo AltoEDR: CrowdstrikeOther tools: Darktrace and M365 Defender

Preferred skill sets:

SOC

Years of experience required:

4-8 Years

Education qualification:

B.Tech/MCA/MBA with IT background/ Bachelor’s degree in Information Technology, Cybersecurity, Computer Science

Professional Certifications like CEH, CCSE, CCNA, Security+, etc., will be plusSIEM certifications

Education (if blank, degree and/or field of study not specified)

Degrees/Field of Study required: Master of Business Administration, Bachelor of Engineering

Degrees/Field of Study preferred:

Certifications (if blank, certifications not specified)

Required Skills

Microsoft Defender, Palo Alto Cortex XSOAR, Splunk

Optional Skills

SoCs

Desired Languages (If blank, desired languages not specified)

Travel Requirements

Available for Work Visa Sponsorship?

Government Clearance Required?

Job Posting End Date

Confirm your E-mail: Send Email
All Jobs from PwC Public Sector