Job descriptionJob description - Handling critical incidents/escalations, reviewing incidents and tracking towards closure - Good experience in SIEM tools, event logging and event analysis - Good knowledge in enterprise security products like Firewalls, EDR, IPS, Web/content Filtering tools, Compliance tools - Team Management, performance monitoring and preparing reports on weekly, monthly basis and share to stakeholders as needed - Good knowledge about common security attacks, targeted attacks - Good experience in forensic analysis, Packet Analysis tools like Wireshark, TCP Dump etc - Good knowledge in Enterprise Security architecture - Knowledge of compliance requirements and audits - Assisting, mentoring L3/L2 analysts and grooming them to move to next level - Contribute to continuing monitoring and improvement of security posture of the organization - Having experience of managing team of 15+ team members across multiple locations. Desired Knowledge, Experience - Desire and ability to stay abreast of current and emerging technologies and apply them appropriately to business challenges - Strong analytical and conceptual skills being a self-starter - Experience with data gathering, complex data analysis and developing standardized reporting to support large organizational decision/support - IT Financial Analysis and Reporting Experience Desired Skills - Understanding of CrowdStrike, Cortex XSIAM, Google Chronicle. - Understanding of Incident, Change, and Problem Management (ITIL) - Understanding of Cyber Security incidents - Understanding of Virtualization technologies - Hands-on experience in Event Monitoring Tools - Understanding of Network, Server, AD, DC infrastructure Qualification- 10 years (relevant experience is must) - SIRT/SIEM and incident response/8-10 Years minimum exp in SIRT, incident handling, - BE, BTech, MTech, MSc CISSP / GCIH Skills/Exposure • Experience in Leading and managing Global Security Operations Center - Proficient in Incident Management and Response - Experience in security device management and SIEM (RSA / Splunk) - In-depth knowledge of security concepts such as cyber-attacks and techniques, threat vectors, risk management, incident management etc. - Experience in threat management - Knowledge of Operating Systems, applications, databases, middleware to address security threats against the same. - Proficient in preparation of reports, dashboards and documentation - Excellent communication and leadership skills - Experience in performing vendor management - Good Analytical skills, Problem solving and Interpersonal skills - Ability to handle high pressure situations with key stakeholders - Experience in Threat Intelligence and Deception.