Appaling points:
- Lead advanced cybersecurity investigations by handling high-severity incidents, threat hunting, root cause analysis, and incident response activities.
- Work with leading security technologies including Microsoft Sentinel, SIEM platforms, threat intelligence, and advanced security monitoring tools.
- Drive continuous security improvement by enhancing incident response processes, developing playbooks, and collaborating with global security teams.
Annual Salary : 12 Million and Above
Key Responsibilities:
- Act as an escalation point for high and critical severity security incidents, and conduct thorough investigations to determine potential impact and understand extend of compromise;
- Analyse attack patterns, Tools, Techniques and Procedures (TTPs) to identify methods of attacks and attack life cycle;
- Provide recommendations on issue resolution activities such as security controls policy configuration changes and security hygiene improvement;
- Provide guidance on mitigating risks associated with security vulnerabilities;
- Hunt for Indicators of Compromise (IOCs) and signs of Advanced Persistent Threats (APTs) within the Client’s environment;
- Conduct threat hunting by means of in-depth log analysis to identify potential threats that may have evaded automated detection;
- Conduct analysis to gather evidence, validate root cause and analyse extend of compromise leveraging Client’s security toolset;
- Identify gaps and weaknesses in existing security processes and propose enhancements to improve Client’s established incident response methodologies;
- Collaborate with cross-functional teams, to ensure end to end management of security incident lifecycle;
- Document and update incident response processes, define outcomes for future references and drive continuous improvement;
- Participate in regular team meetings, Incident Response war room discussions and executive briefing sessions.
- Minimum 2+ years of experience as a SOC L3 Analyst working as part of a Global SOC team.
- Resolve, escalate, report, and raise recommendations for resolving and remediating security incidents.
- Be an escalation point for investigations of clients and suggest optimization activities to improve their performance.
- Proactively monitor and review threats and suspicious events from customers participating in the service.
- Handle the advanced monitoring of system logs, SIEM tools, and network traffic for unusual or suspicious activity.
- Set up SIEM solutions and troubleshoot connectivity issues. · Investigate and resolve security violations by providing post-mortem analysis to illuminate issues and possible solutions.
- Collate security incident and event data to produce monthly exception and management reports.
- Report unresolved network security exposure, misuse of resources, or noncompliance situations using defined escalation processes.
- Assist and train team members in the use of security tools, the preparation of security reports, and the resolution of security issues.
- Develop and maintain documentation for security systems and procedures.
Required Skills & Qualifications:
- Maintain excellent customer satisfaction through professional, proactive and personal service.
- Experience with SIEM vendors such as QRadar, ArcSight, RSA, and LogRhythm (preferred is 2 tool backgrounds)
- Experience in incident response, and in writing procedures runbooks and playbooks ·
- The project technology is Microsoft Sentinel.
Japanese Language : Business level Japanese (JLPT N2) and Business level English.
Company Description:
The Company is a global provider of Digital Business Transformation, Digital Engineering, and Information Technology (IT) outsourcing services that accelerate our clients’ journey to their Digital Future. Company serves Global 2000 companies in Banking, Financial Services, Insurance, Healthcare, Telecommunications, Media, Entertainment, Travel, Manufacturing, and Technology industries. Using a combination of digital strategy, digital engineering, business implementation, and IT platform modernization services, Company helps clients execute successful end-to-end digital business transformation initiatives.
. Skillset Required: cybersecurity, crowdstrike, management, endpoint security, information security