We are seeking a Cyber Security Analyst who is passionate about IT security and dedicated to strengthening our defences
This role is based in Mumbai and involves working as part of a small, agile security team, with the Cyber Security head located in Singapore
The ideal candidate enjoys the challenge of hunting for vulnerabilities and identifying gaps in our systems
They are enthusiastic and proactive, always taking the initiative to enhance our security posture
In this role, you will work with advanced cybersecurity tools such as Qualys, SentinelOne, IronPort, IronScales, Palo Alto firewalls, Delinea Privilege Manager, BeyondTrust Privileged Access Management, and Devo SIEM
You will play a critical part in monitoring and responding to security threats, investigating incidents, and collaborating with the IT Infrastructure team, in-house developers, Database Administration team, and the IT Compliance Manager to ensure our systems are secure and resilient
Required Skills:
Security Operations Experience : Minimum of 5 years of hands-on experience in security operations, incident response, or threat intelligence roles.
SIEM Expertise : Extensive experience working with SIEM platforms, including the ability to configure, tune, and create custom rules. Proficiency in using SIEM for forensic investigation during security incidents is critical.
Network Security Knowledge : Strong understanding of network protocols and experience with Palo Alto firewalls, VPNs, IDS/IPS, and endpoint security solutions like SentinelOne.
Incident Response Expertise : Proven ability to analyse and respond to security incidents, including malware analysis, intrusion detection, and vulnerability assessments. Experience in developing and implementing incident response plans and playbooks.
Forensics and Investigation : Detail-oriented professional with strong skills in conducting thorough forensic investigations using SIEM data and other tools, digging deep to uncover root causes and suggest effective preventative measures.
Vulnerability Management : A proactive approach to identifying and addressing vulnerabilities, with experience in performing regular vulnerability assessments using Qualys and coordinating remediation efforts.
Scripting and Automation : Familiarity with scripting languages (eg, Python, PowerShell) for automation and analysis. Experience with security orchestration, automation, and response (SOAR) tools is a plus.
Azure Security : Awareness of Azure cloud security is beneficial.
Privilege Management : Experience with privilege management solutions is an advantage.
Email and Endpoint Security : Familiarity with email security solutions like IronPort and IronScales.
Communication Skills : Strong and proficient English communication skills, with the ability to write clear and concise documentation and collaborate effectively with technical and non-technical teams.
Certifications (Preferred): Relevant certifications such as CISSP, CISM, CHFI, CEH, or GIAC are highly desirable.
Problem-Solving and Analytical Skills : Enthusiastic and proactive, with strong analytical skills to identify, analyse, and resolve security threats. A commitment to staying updated with emerging security threats and trends is essential.
Responsibilities:
Monitor and Analyse Security Events : Continuously monitor and analyse security events and alerts from the SIEM and other sources to identify potential threats.
SIEM Rule Management : Configure, tune, and create custom SIEM rules to improve detection capabilities. Regularly review and refine these rules to reduce false positives and enhance accuracy.
Email Security Analysis : Assist in identifying and classifying reported and quarantined emails, determining whether they are phishing attempts, spam, or false positives, and taking appropriate action based on the findings.
Incident Investigation and Reporting : Use SIEM data and other tools to conduct thorough investigations of security incidents, providing detailed reports on findings, and responding to incidents in a timely and effective manner.
Incident Response Development : Develop and implement incident response plans and playbooks, ensuring readiness to address security incidents.
Playbook Contribution : Contribute to writing detailed incident response playbooks and ensure they are followe'd meticulously, helping to standardize and enhance our incident response processes.
Vulnerability Assessments : Perform regular vulnerability assessments and work with relevant teams to coordinate and implement remediation efforts.
Privilege and Access Management : Manage and monitor privileged access, with experience in privilege management solutions being an advantage.
Collaboration : Work as part of a small security team, and collaborate with the IT Infrastructure team, in-house developers, Database Administration team, and the IT Compliance Manager to enhance the overall security posture of the organization.
Stay Updated : Stay informed about the latest security trends, threats, and technologies, integrating relevant intelligence into security operations.
Education:
Degree : bachelors degree in Computer Science, Information Security, or a related field. Equivalent work experience may be considered