Upload Button Icon Add office photos
filter salaries All Filters

10 Align Knowledge Centre Jobs

Align Group - Cyber Security Engineer - Threat Modeling (8-12 yrs)

8-12 years

Align Group - Cyber Security Engineer - Threat Modeling (8-12 yrs)

Align Knowledge Centre

posted 1d ago

Job Description

- Experience:

- 4+ years of experience in cybersecurity with at least 2 years focusing on threat intelligence or incident response.

- Experience working in a SOC or MSSP environment preferred.

- Strong familiarity with threat intelligence platforms, SIEMs, and security analytics tools.

- Experience with threat intelligence sources (OSINT, commercial feeds) and frameworks like MITRE ATT&CK.

Certifications : One or more of the following (or equivalent) :

- GIAC Certified Threat Intelligence Analyst (GCTI)

- Certified Information Systems Security Professional (CISSP)

- Certified Ethical Hacker (CEH)

- SANS Cyber Threat Intelligence (CTI) certification

1. Threat Intelligence Gathering and Analysis :

- Continuously monitor and collect data from a variety of internal and external threat intelligence sources, including open-source intelligence (OSINT), commercial feeds, and dark web monitoring.

- Analyze threat actor tactics, techniques, and procedures (TTPs) using frameworks like MITRE ATT&CK to understand potential impact on client environments.

- Identify new and emerging threats, vulnerabilities, and exploits that could affect MSSP clients.

- Conduct deep-dive research into cyber threat activity groups, campaigns, and malware to provide actionable intelligence to SOC teams.

2. Threat Reporting and Dissemination :

- Develop and distribute threat intelligence reports to SOC analysts and clients, including daily, weekly, and monthly intelligence updates.

- Create tailored threat briefs for specific industries or clients based on their environment and threat profile.

- Collaborate with SOC and incident response teams to ensure threat intelligence is utilized effectively in detection rules, playbooks, and incident response activities.

- Provide timely alerts and threat advisories to clients regarding active or emerging threats.

3. Integration with SOC Operations :

- Work closely with SOC analysts to integrate threat intelligence into existing monitoring, detection, and response workflows.

- Enrich SIEM alerts and incident investigations with threat intelligence to improve context and accuracy of detections.

- Help develop and tune detection use cases and correlation rules based on threat intelligence and evolving adversary behaviors.

- Provide input into incident response playbooks and processes, ensuring they are aligned with the latest threat intelligence.

4. Threat Hunting Support :

- Support the SOC team in proactive threat hunting activities by identifying indicators of compromise (IOCs) and providing guidance on where to focus investigations.

- Assist in identifying advanced persistent threats (APTs), malware infections, and other high-risk activities within client environments.

- Develop and share hunting hypotheses with SOC teams based on the latest intelligence and observed attack patterns.

5. Threat Intelligence Platform (TIP) Management :

- Manage and maintain the organization's Threat Intelligence Platform (TIP) and ensure it integrates with the SIEM and other security tools.

- Curate threat intelligence feeds and prioritize intelligence that is most relevant to MSSP clients and their industries.

- Perform regular updates and quality checks on IOCs, threat indicators, and intelligence data within the TIP.

- Ensure that threat intelligence data is actionable, timely, and relevant to improve operational SOC effectiveness.

6. Collaboration with External Threat Intelligence Communities :

- Participate in threat intelligence sharing communities, Information Sharing and

- Analysis Centers (ISACs), and trusted industry networks.

- Share relevant intelligence and receive updates from industry peers, law enforcement, and government agencies.

- Stay current on the global threat landscape by attending conferences, webinars, and engaging in continuous learning opportunities.

7. Threat Intel Automation and Analytics :

- Implement automation where possible to streamline the ingestion and analysis of threat intelligence data.

- Use data analytics to identify patterns in threat intelligence and produce predictive insights for clients.

- Collaborate with the security engineering team to automate the integration of IOCs and threat indicators into detection platforms.

8. Client Interaction and Customization :

- Work directly with MSSP clients to understand their specific threat landscape, industry challenges, and business requirements.

- Provide threat intelligence briefings tailored to client-specific concerns, such as sectoral threats or geopolitical risks.

- Assist clients with identifying and mitigating threats specific to their environment through actionable intelligence.

- Contribute to periodic client meetings by delivering updates on emerging threats, industry trends, and recommendations for improving security posture.

9. Training and Knowledge Sharing:

- Provide ongoing training and threat intelligence updates to SOC teams to enhance their awareness of the current threat landscape.

- Develop knowledge-sharing resources like threat intelligence dashboards, wikis, and threat actor profiles for use by internal teams and clients.

- Mentor junior SOC analysts in understanding and applying threat intelligence in day-to-day operations.


Functional Areas: Software/Testing/Networking

Read full job description

Compare Align Knowledge Centre with

TCS

3.7
Compare

Accenture

3.9
Compare

Wipro

3.7
Compare

Cognizant

3.8
Compare

Capgemini

3.8
Compare

HDFC Bank

3.9
Compare

ICICI Bank

4.0
Compare

Infosys

3.7
Compare

HCLTech

3.5
Compare

Tech Mahindra

3.6
Compare

Genpact

3.9
Compare

Teleperformance

3.9
Compare

Concentrix Corporation

3.8
Compare

Axis Bank

3.8
Compare

Amazon

4.1
Compare

Jio

3.9
Compare

Reliance Retail

3.9
Compare

IBM

4.1
Compare

iEnergizer

4.7
Compare

LTIMindtree

3.8
Compare

Similar Jobs for you

Cyber Security Engineer at Tata Elxsi

5-7 Yrs

₹ 15-20 LPA

Security Architect at MINDTEL GLOBAL PRIVATE LIMITED

5-7 Yrs

₹ 15-20 LPA

Cyber Security Analyst at Hirein5

5-10 Yrs

₹ 10-30 LPA

Cyber Security Engineer at XANDER CONSULTING AND ADVISORY PRIVATE LIMITED

7-15 Yrs

₹ 30-60 LPA

Cyber Security Analyst at Maple Cloud Technologies

4-8 Yrs

₹ 12-22 LPA

Cyber Security Engineer at MNR Solutions

7-12 Yrs

₹ 17-22 LPA

Cyber Security Consultant at Infinitsys Solutions Pvt Ltd

8-11 Yrs

₹ 25-28 LPA

Cyber Security Engineer at Talent Monitor

8-13 Yrs

₹ 20-36 LPA

Information Security Engineer at WTW GLOBAL DELIVERY AND SOLUTIONS INDIA PVT LTD.

6-12 Yrs

₹ 17-22 LPA

Cyber Security Engineer at icc staffing services

5-8 Yrs

₹ 16-30 LPA

Salesforce Marketing Cloud Engineer (5-9 yrs)

5-9 Yrs

7d ago·via hirist.com

RPA Developer - UiPath (4-14 yrs)

4-14 Yrs

1mon ago·via hirist.com

RPA Solution Architect (8-15 yrs)

8-15 Yrs

1mon ago·via hirist.com

Software Engineer - SOAR Platform (5-8 yrs)

5-8 Yrs

2mon ago·via hirist.com

Splunk Developer - Load Balancing Tools (5-10 yrs)

5-10 Yrs

6mon ago·via hirist.com
write
Share an Interview