Must-Have Skills(Should be proper knowledge) SOAR SIEM AWS Ability to build an API portal using Python
Nice to Have : KubernetesJob Summary:We are seeking a skilled Sr
Security Engineer to monitor, detect, analyze, and respond to security incidents affecting our SPC environment
The ideal candidate will use automation to streamline SOC operations and enhance incident response capabilities
This role requires strong oral and written communication, analytical problem-solving skills, sound judgment, and a solid foundation in IT security
Job Responsibilities: Security Monitoring: Utilize SIEM and other tools to detect security incidents and anomalies
Incident Analysis: Investigate and analyze security incidents, determine root causes, assist in vulnerability assessments, and manage remediation efforts
Automation Development: Create and implement automation scripts and workflows to improve SOC efficiency, including incident response automation and playbook creation
Log Analysis: Perform in-depth analysis of logs to identify indicators of compromise (IOCs) and potential security breaches
Response Planning: Develop and maintain incident response plans and procedures to ensure optimal responses to security incidents
Collaboration: Coordinate with analysts and stakeholders to escalate and respond to security incidents promptly
Mentorship: Provide guidance and mentorship to analysts on incident detection, analysis, and response techniques
Exercises and Simulations: Participate in security incident tabletop exercises and simulations to test and improve incident response capabilities
Continuous Learning: Stay up-to-date with the latest cybersecurity threats, vulnerabilities, and mitigation techniques
Process Improvement: Contribute to SOC process improvements and tool enhancements and generate SLI/SLO-related metrics to show improvement
Subject Matter Expertise: Act as an information security subject matter expert for the Incident Response team and assist with escalations
Travel Requirements: Yearly travel of approximately 1-2 weeks may be required, subject to change based on business needs
Qualifications and Requirements: IT and Security Knowledge: Solid understanding of IT and security best practices
Cloud Experience: Hands-on experience with one or more cloud platforms (AWS, Azure, GCP) is desired but not required
Team Collaboration: Strong ability to collaborate with cross-functional teams
Network Knowledge: Basic understanding of network routers, switches, and firewalls
Automation Skills: Passion for automation, performance, reliability, and solving complex security challenges using Python
Linux Proficiency: Strong Linux proficiency, including security hardening for Linux, web applications, and databases such as PostgreSQL and MariaDB
Kubernetes Experience: Experience with Kubernetes is a plus
Security Tools: Familiarity with open-source security tools and applications
Attention to Detail: Excellent attention to detail and organizational skills
Availability: Willingness to work in a 24/7 environment, including weekends and holidays, with on-call duties
Experience: 5+ years of experience in a related fiel