Senior Associate
PricewaterhouseCoopers Services Trust
Apply to this jobLine of Service
AdvisoryIndustry/Sector
FS X-SectorSpecialism
OperationsManagement Level
Senior AssociateJob Description & Summary
A career within Cybersecurity and Privacy services, will provide you with the opportunity to help our clients implement an effective cybersecurity programme that protects against threats, propels transformation, and drives growth. As companies pivot toward a digital business model, exponentially more data is generated and shared among organisations, partners and customers. We play an integral role in helping our clients ensure they are protected by developing transformation strategies focused on security, efficiently integrate and manage new or existing technology systems to deliver continuous operational improvements and increase their cybersecurity investment, and detect, respond, and remediate threats.JOB DESCRIPTION
L2 SOC Analyst
A career within Cybersecurity and Privacy services, will provide you with the opportunity to help our clients implement an effective cybersecurity programme that protects against threats, propels transformation, and drives growth. As companies pivot toward a digital business model, exponentially more data is generated and shared among organisations, partners and customers. We play an integral role in helping our clients ensure they are protected by developing transformation strategies focused on security, efficiently integrate and manage new or existing technology systems to deliver continuous operational improvements and increase their cybersecurity investment, and detect, respond, and remediate threats.
The L2 Analyst will be responsible for regular operations, continuous improvement processes & managing client & vendor interactions. The individual will also be required to coach L1 analysts in acquiring necessary skills. This opportunity is for experienced professionals with a strong passion for helping firms improve their cyber security posture. The person receives incidents escalated from L1, and work towards remediation of the incidents found. He/she continuously operates the Security Incident process, driving the resolution of identified issues, bringing the necessary experience and expertise above the existing L1 SOC analysts.
Technology
Desired Skills and Experience:
- Bachelor’s degree with 2-4 years of experience in cyber security solutions & SOC operations
- Good communication skills both written and oral
- Should have experience of working on SMB and Enterprise clients
- Good understanding of ITIL processes, including Change Management, Incident Management and Problem Management
- Should have strong expertise on SIEM tools & other devices found in SOC environment
- Should have good knowledge in firewalls, IDS/IPS, AVI, EDR, Proxy, DNS, email, AD, etc.
- Good understanding in raw Log formats of various security devices like Proxy, Firewall, IDS/IPS DNS
- Good understanding of networking concepts (TCP/IP, LAN/WAN, Internet network topologies)
- Preference will be given to certified professionals like CEH.
- A strong work ethic with good time management skills
- Ability to mentor and encourage junior teammates to build a cohesive, motivated unit
Key Duties & Responsibilities
- Provide analysis and trending of security log data from many IT security devices
- Provide Incident Response (IR) support when analysis confirms actionable incident
- Provide threat and vulnerability analysis as well as security advisory services
- Analyse and respond to previously undisclosed software and hardware vulnerabilities
- Investigate, document, and report on information security issues and emerging trends
- Integrate and share information with other analysts and other teams
- Assist Entry-Level SOC analysts to help them build stronger skills
- Assist Team Leads with reporting, projects, administrative work as needed
- Review SOC Analyst ticket queue, review tickets, closure or reassignment as needed
- Create/review/modify documentation as needed, to include any process or procedure and thus ensure it’s up to date and standard
- Change management calendar updates/closures
- Create Daily/Weekly/ Monthly SOC Reports & provide other necessary updated
- Answer SOC incoming phone calls and triaging phone calls that are not related to monitoring
- Create daily Shift Handoff notes and summary and send to all shifts
- Other duties as assigned by Team Leads and/or Operations Manager
- Review/ Create new use cases based on new attack trends
- Event Analysis Ability to understand and interpret Windows, Linux OS, firewall, web proxy, DNS, IDS, and HIPS log events. Ability to pivot between events and correlate host and network events. Understanding of Windows and UNIX event logs must be enough to create correlation searches for Windows and Linux events.
- • Develop/maintain threat detection rules.
- • Develop threat detection rules, parsers, and use cases.
- • Ability to understand security analytics and flows across various SaaS applications and cloud computing tools.
- • Having a naturally analytical mind and interest in analysing large volumes of data and suggesting use cases.
- • Validate use cases by selective use case testing and logic examination.
- • 2-4 years of experience analysing malicious traffic and building detections.
- • 2-4 years of experience in applications security, network security, and systems security.
- • Knowledge of MITRE or similar frameworks and procedures used by adversaries.
- • SIEM Solutions: Securonix/Splunk/Sumologic/LogRhythm/ArcSight/Qradar
Mandatory Skill Set-Logrhtym, QRadar
Preferred Skill Set-Logrhtym, QRadar
Year of experience required-2-10
Qualifications-BE, Btech, ME, Mtech
Education (if blank, degree and/or field of study not specified)
Degrees/Field of Study required:Degrees/Field of Study preferred:Certifications (if blank, certifications not specified)
Required Skills
IBM QRadar, LogRhythmOptional Skills
QRadar SIEMDesired Languages (If blank, desired languages not specified)
Travel Requirements
Not SpecifiedAvailable for Work Visa Sponsorship?
NoGovernment Clearance Required?
NoJob Posting End Date
Summary
Manage cybersecurity operations, mentor junior analysts, and respond to incidents.
Job title
Senior Associate
Experience level
2-4 years
Industry
financial services
Location requirements
Kolkata location, remote work not allowed.
Salary
Not specified
Management role
No
Required skills
Preferred skills
Specializations
Structured locations inferred from the posting.
South City, Ayali Khurd, Punjab, India