Your browser does not support javascript! Please enable it, otherwise web will not work for you.

SOC Analyst @ Capgemini

Home > IT Security

 SOC Analyst

Job Description

Role & responsibilities


The Security Operation Center (SOC) Analyst's daily duties include operational support of the Security Event and Information System and various other security services.

Primary Skills: -

SIEM (Exabeam Data Lake & Analytics, Fortisiem), Service Now, EDR (CrowdStrike), DLP(Forcepoint),

Secondary Skills: -

Microsoft Azure, Email Gateway (Avanan), Cisco Umbrella, Okta.

Responsibilities

The Security Operation Centre (SOC) Analyst will:

  • Monitor the Security Event and Information Systems (SIEM) by daily review and analysis of alerts generated. Perform incident response activities of anomalies, triage, and escalation of daily alerts, as necessary.
  • Monitor the Data Loss Prevention (DLP) by daily review of alerts generated. Perform initial investigation of anomalies, triage, and escalation of daily alerts, as necessary.
  • Monitor reported Spam and Phishing emails, perform basic investigation, quarantine, and escalate incidents, as necessary.
  • Meet USI defined SLA for security incident: Mean Time To Detect (MTTD) and Mean Time To Respond (MTTR).
  • Monitor, Configure, Develop, Design, Architect, Implement, Acquire, Operate systems in accordance with:
  • USI Policies for the Information Security Program (PISP)
  • Standards for the Information Security Program (SISP)
  • Keep up to date with security updates and improvements to safeguard information system assets by identifying and solving potential and actual security problems.
  • Protect systems against damage, changes, or illegal access by defining access privileges, control structures, and resources.
  • Recognize problems by identifying abnormalities and reporting violations.
  • Implement security improvements by assessing current situation; evaluating trends; anticipating requirements.
  • Determine security violations and inefficiencies by conducting periodic audits.
  • Other security duties, as assigned.

Knowledge, Skills And Abilities

  • Ability to understand and correlate data from multiple sources, not limited to user authentication events, windows security event logs, syslog, NetFlow/PCAP data, DHCP logs, DNS logs, intrusion detections alerts, proxy logs, packet captures, and firewall events.
  • Knowledge of various security methodologies and processes, and technical security solutions is a plus.
  • Understanding of how both Windows, Linux and network platforms are compromised is a plus.
  • Technical IT experience as a Help Desk Analyst or Security/Network Administrator or equivalent knowledge.
  • Knowledge of Microsoft Active Directory, Group Policy, DNS, Certificate Services, DHCP.
  • Previous Security Operations Center (SOC) experience is a plus.
  • Experience with Security Information and Event Management (SIEM) tools is a plus.
  • Solid understanding of IP networking fundamentals, including IPv4, TCP/IP, LAN/WAN design theory, static and dynamic routing protocols, NAT, ACLs, etc.
  • Knowledge of scripting languages such as Python or PowerShell is a plus.
  • Solid understanding of cyber forensics concepts including malware, hunt, etc. is a plus.
  • Associates Degree in Computer Information Systems, Cyber Security, Computer Science or related.
  • Security Certifications Preferred: CompTIA: Security+, Network+; GSEC: GIAC Security Essentials, GISG: GIAC Information Security Fundamentals
  • Familiar with governance and compliance concepts, practices, and procedures, which includes but is not limited to HIPAA, PCI-DSS, ISO, NIST, SOX, GDPR, CCPA, NAIC.

Skills

  • Reading Comprehension - Understanding written sentences and paragraphs in work related documents.
  • Critical Thinking - Using logic and reasoning with attention to details, to identify the strengths and weaknesses of alternative solutions, conclusions or approaches to problems.
  • Complex Problem Solving - Identifying complex problems and reviewing related information to develop and evaluate options and implement solutions.
  • Speaking - Talking to others to convey information effectively.
  • Writing - Communicating effectively in writing as appropriate for the needs of the audience.
  • Judgment and Decision Making - Considering the relative costs and benefits of potential actions to choose the most appropriate one.
  • Time Management - Managing one's own time and the time of others in a deadline driven environment.
  • Service Orientation - Actively looking for ways to help people.

Experience

  • 1+ years' experience as an analyst in Information Security in a corporate IT department/NOC/SOC
  • 1+ years of experience with security products, such as SEIM, DLP, NGAV, Vulnerability Scanners, URL Filters, Email security tools.
  • Previous experience monitoring, analysing, and escalating, security incidents from multiple sources.
  • Ability to effectively communicate in a technical team environment.

Job Classification

Industry: IT Services & Consulting
Functional Area / Department: IT & Information Security
Role Category: IT Security
Role: Cyber Security
Employement Type: Full time

Contact Details:

Company: Capgemini
Location(s): Hyderabad

+ View Contactajax loader


Keyskills:   Edr SIEM Dlp EXABEAM

 Fraud Alert to job seekers!

₹ Not Disclosed

Similar positions

Associate Principal Engineer MDM-Absolute Endpoint

  • Unisys
  • 8 - 10 years
  • Hyderabad
  • 6 days ago
₹ Not Disclosed

Senior IAM Analyst

  • OneAdvanced
  • 6 - 11 years
  • Bengaluru
  • 22 days ago
₹ Not Disclosed

Cyber Security Analyst

  • Ramco Systems
  • 4 - 7 years
  • Chennai
  • 22 days ago
₹ Not Disclosed

Security Analyst

  • Ahead
  • 3 - 8 years
  • Noida, Gurugram
  • 29 days ago
₹ Not Disclosed

Capgemini

Capgemini Engineering combines, under one brand, a unique set of strengths from across the Capgemini Group: the world leading engineering and R&D services of Altran acquired by Capgemini in 2020 - and Capgemini's digital manufacturing expertise. With broad industry knowledge and cutting-edge ...