Upload Button Icon Add office photos
filter salaries All Filters

8 Intuitive Apps Jobs

Cyber Security Engineers

5-8 years

Chennai

1 vacancy

Cyber Security Engineers

Intuitive Apps

posted 1y ago

Job Description

  • The candidate should have a team-oriented, client-facing mindset with proven experience conducting EDR infrastructure deployments. Use deep insights to identify, recommend and execute resolution for malware and other EDR-detected incidents while helping to develop and execute methodologies for EDR deployment, feature enablement and technical integration in a SOC.
  • As an Endpoint Detection and Response (EDR) SME, candidate will play a key role in supporting the design, deployment, configuration, optimization, and operation of a large-scale Endpoint Detection and Response (EDR) deployment solution or similar security products, across multiple geographies.
  • Candidate shall be responsible for managing day to day operations of Security Device Management SIEM, incident response, threat hunting, Use case engineering, SOC analyst, device integration with SIEM. Also Responsible for identifying, reporting and tracking system vulnerabilities within corporate, commercial and federal assets ensuring the integrity of the environment

Qualifications

  • Experience in a cybersecurity role in a large size enterprise
  • Excellent analytical and problem-solving skills with attention to detail
  • Experience with deployment of an EDR solution in a large customer environment, including 15k+ endpoints
  • Knowledge of intrusion detection methodologies and techniques for detecting host and network- based intrusions
  • Experience with providing status reports, including metrics and KPIs, for team activities
  • Knowledge of network security architecture concepts including topology, protocols, components, and principles
  • Knowledge of various enterprise operating system (OS) configurations and management tools for use during deployment, configuration, and management of EDR solutions
  • 3+ years of experience with deployment, configuration, or maintenance of supporting enterprise EDR solutions, including Carbon Black EDR, CrowdStrike Falcon (is a plus), SentinelOne, FireEye HX, McAfee, Tanium, etc.
  • 3+ years of experience with performing systems administration, including basic troubleshooting and installation, monitoring system performance or availability, performing security upgrades, and optimizing solution configurations to meet the needs of operational users
  • 3+ years of experience in EDR and/or AV; previous work in malware and attack analysis, research, investigation, and response role by performing forensic analysis of logs and packet captures to identify malicious artifacts
  • 2+ years of experience in working with a Security Operations Center (SOC) environment, leveraging EDR tools to support incident response, vulnerability scanning, threat hunting, network monitoring and log management, and compliance management activities
  • +3 years of experience with a solid understanding of the TCP/IP protocol suite, security
  • architecture, and common TTP s (tactics, techniques, and procedures) used by threat actors
  • Experience in performing and analyzing both log and packet data to perform incident response in a SIEM environment (Splunk, NetWitness, Azure Sentinel, etc.) and identify potential compromises to customer networks.
  • Knowledge of federal information security policies, standards, procedures, directives, frameworks, federal security authorizations, assessment, and risk management processes for enterprise systems
  • Strong verbal/written communication and interpersonal skills are required to document and communicate findings, escalate critical incidents, and interact with customers
  • Experience using ticketing systems for tracking (WebHelpDesk, Remedy, OpsConsole, ServiceNow, etc.)
  • Candidate must possess, at least one, applicable professional/technical certifications, such as Security +, C|EH, OSCP, GCIH, CISSP, GPEN, GWAPT, GISEC, CISM, CrowdStrike Certified Falcon Hunter, Responder, Administrator, or CISA
  • Experience in Automation orchestration technologies: such as SOAR, Ansible, Puppet, Chef
  • Experience in Coding languages: such as Python, PowerShell, Perl, C/C++, Java, etc.
  • Unix/Linux RedHat windows Administration
Skills Required
  • Project and delivery management experience 3+ years EDR administration (CrowdStrike Falcon, VMware Carbon Black, Palo Alto Network Cortex XDR, Microsoft Windows Defender, Cylance, Tanium etc.)
  • 3 + years of working with EDR tools performing requirements gathering, deployment, configuration, and conducting threat hunting
  • 5+ years working with operational information security disciplines (e.g. incident response, security infrastructure management, or monitoring services)
  • 3+ years security tool engineering and administration (e.g. NGAV, EPP, EDR, SIEM, SOAR, UEBA, Deception, Attack Surface Management, etc.)
  • Some of the following EDR experience- Agent deployment, health check and coverage sustainability
  1. - Threat Hunting
  2. - Systems integration
  3. - Comparing vendor functionality
  4. - Mapping EDR capabilities to threat scenarios
  5. - Deploying EDR in a multi-agent (i.e. AV, NG AV) environments
  6. - Deep understanding and proven experience in Cybersecurity Operations (Monitoring, Detection, Incident Response, Forensics)
Personal skills:
  • Good Team player
  • Possess Positive and learning attitude
  • Good Verbal and Written communication skills
  • Sense of Ownership, Priorities and Autonomous
  • Ability to travel up to 50% of the time
Roles & Responsibilities
 
As an Endpoint Detection and Response (EDR) Tools Engineer, the candidate will be part of the Cyber security team responsible for deploying, operating, and maintaining the global EDR platform. The candidate will provide support for EDR tools in the environment. The candidate must be able to communicate with the Security Operations and Incident Response teams to identify adjustments and modifications to be made to the EDR toolset. As in the most senior EDR tools engineer position, the candidate must be able to lead and by example to drive progress forward.
  • Lead and oversee deployment, operation, and maintenance of the global EDR platform
  • Provide support response to other security teams in respect to the EDR platform
  • Identify adjustments and modifications for configuration
  • Identify new opportunities for tools to incorporate into the EDR platform
  • work with cross functional teams to identify the right mix of processes and technology to implement solutions to support the needs of the internal and external customers.
  • Continually work on the optimization of EDR and integrated solutions, including refinement data produced, development of automated workflows or playbooks, and integration of the EDR data with complementary security solutions, including SIEM, SOAR, etc.
  • Establishing technical processes and tools focused on the incident response lifecycle. Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Event Activity.
  • Work to integrate cybersecurity data using enterprise or custom tools data aggregation and analysis tools, including Splunk and similar complementary security solutions.
  • Manage projects to completion both individually and in a group as well as mentoring others and orchestrating team efforts for problem solving
  • Serve as an escalation point to triage and remediate security events in a SOC environment by leveraging data collected from security solutions.
  • Provide support in an operations and maintenance role, including ticket work information updates, issue responses, and remediation.
  • Provide content on deliverables, including written reports and technical documents, SOPs and configuration guides, and training and briefing materials
  • Collaborate and consult with peers, colleagues, and managers, etc. to resolve issues and achieve goals
  • General SIEM monitoring, analysis, content development, and maintenance.
  • Daily security activities related to the protection of corporate and other federal assets including scanning tools and ticketing systems documenting the identification and remediation process for identified system flaws
  • Provide information to system owners of flaws identified within that groups responsible systems.
  • Assist in risk assessment duties including reporting and oversight of remediation efforts
  • Research, analysis, and response for alerts; including log retrieval and documentation.
  • Conduct analysis of network traffic and host activity across a wide array of technologies and platforms.
  • Assist in incident response activities such as host triage and retrieval, malware analysis, remote system analysis, end-user interviews, and remediation efforts.
  • Enterprise-level experience managing the remediation of vulnerabilities in two or more of the following areas:
  • Server Operating Systems (Windows Server, Red Hat, CentOS)
  • Network (Cisco, Fortinet, Palo Alto, F5, McAfee)
  • Storage (NetApp, CleverSafe)
  • Manage multiple projects with various priority levels and time lines from start to finish
  • Develop and maintain accurate documentation for internal procedures and services
  • Maintain knowledge of outstanding vulnerability management issues and ensure remediation timelines are completed by required guidelines
  • Thorough understanding of how to calculate CVSS v2 and v3 adjusted scores
  • Must collaborate with other departments to resolve complex issues and be detail oriented

Employment Type: Full Time, Permanent

Read full job description

Prepare for Cyber Security Engineer roles with real interview advice

What people at Intuitive Apps are saying

What Intuitive Apps employees are saying about work life

based on 5 employees
67%
100%
50%
100%
Strict timing
Monday to Friday
No travel
Day Shift
View more insights

Intuitive Apps Benefits

Free Transport
Child care
Gymnasium
Cafeteria
Work From Home
Free Food +6 more
View more benefits

Compare Intuitive Apps with

Zoho

4.3
Compare

Freshworks

3.5
Compare

TCS

3.7
Compare

Infosys

3.7
Compare

Wipro

3.7
Compare

HCLTech

3.6
Compare

Tech Mahindra

3.6
Compare

LTIMindtree

3.8
Compare

Persistent Systems

3.5
Compare

Mphasis

3.4
Compare

Accenture

3.9
Compare

Cognizant

3.8
Compare

Capgemini

3.8
Compare

HDFC Bank

3.9
Compare

ICICI Bank

4.0
Compare

Genpact

3.9
Compare

Teleperformance

3.9
Compare

Concentrix Corporation

3.8
Compare

Axis Bank

3.8
Compare

Amazon

4.1
Compare

Similar Jobs for you

Cyber Security Engineer at Cyber Managed Services Inc. (CyberMSI)

Kolkata, Mumbai + 5

2-5 Yrs

₹ 6-10 LPA

CS Analyst at GLOBAL PAYMENTS ASIA-PACIFIC INDIA PRIVATE LIMITED

Pune

6-8 Yrs

₹ 8-10 LPA

Cyber Security Engineer at Advanced Computer Software

Bangalore / Bengaluru

2-5 Yrs

₹ 4-7 LPA

Associate Quality Assurance Manager at Aspen Technology

Bangalore / Bengaluru

3-8 Yrs

₹ 5-10 LPA

Cyber Security Analyst at Gemini Solutions

Panchkula, Gurgaon / Gurugram + 2

3-6 Yrs

₹ 8-10 LPA

Engineer at ATMECS Technologies Pvt., Ltd.

Hyderabad / Secunderabad

5-8 Yrs

₹ 7-10 LPA

Penetration Tester at Gen

Chennai

4-8 Yrs

₹ 6-10 LPA

Penetration Tester at Mercedes Benz Research and Development India Pvt.Ltd.

Bangalore / Bengaluru

3-7 Yrs

₹ 7-11 LPA

Automation Architect at Zerto Ltd

Bangalore / Bengaluru

4-8 Yrs

₹ 6-10 LPA

Security Risk Analyst at PrismHR

Noida

4-8 Yrs

₹ 6-10 LPA

Cyber Security Engineers

5-8 Yrs

Chennai

1y ago·via naukri.com

Intuitive Apps - Credit Risk Analyst (4-7 yrs)

4-7 Yrs

Chennai

2mon ago·via iimjobs.com

Intuitive Apps - Human Resource Role - Payroll Management - BFSI Domain (4-7 yrs)

4-7 Yrs

Mumbai, Navi Mumbai

2mon ago·via iimjobs.com

Big Data Administrator - Hadoop/Spark (7-10 yrs)

7-10 Yrs

Bangalore / Bengaluru, Gurgaon / Gurugram, Nagpur

2mon ago·via hirist.com

Intuitive Apps - AVP - Loan Syndication Process (5-7 yrs)

5-7 Yrs

Chennai

2mon ago·via iimjobs.com

IT Support/ Admin

3-7 Yrs

Mumbai, Navi Mumbai

1y ago·via naukri.com
write
Share an Interview