job description :
- should have performed activities like log source integration, troubleshooting, upgradation, performing dc-dr drill, etc
- ot/ security experience
- use case creation, content development, playbook creation and automation with api's will be added advantage.
- integrate respective solution / technology with every other solution / technology deployed in the soc setup
- automation of all l1 & l2 activities,
- migration of data & logs from client to currently running soc
- collaborate closely with technical account manager (tam) and engineering division of the respective oem for early resolution to the product level cases, vulnerabilities, bugs, features enhancement, patches, versions etc.
- single point of contact to the client stakeholders with respective oem
- maintain the suitable architecture of the technology solution
- perform threat modelling of the client assets and accordingly define the necessary use cases
- execute major changes without any disruption and adverse impact.
- continuously deliver the value of solution to the client terms of detecting all kind threats, accuracy of detection, value added use cases and content development etc.
- improvise threat hunting capabilities of the technology
- continuous development of analytical, statistical, mathematical models leveraging ai/ml capabilities of the technology to threat detection and prediction capabilities and put in place advanced use cases
- continuous fine tuning of configuration, rules, policies etc. continuous innovation and automations in intuitive dashboards, report, queries.
- optimization of response time to fetch data, logs in advanced queries, reports, dashboards etc.
- ensure logs ingestion from data sources, automation of incident, vulnerability etc. remediation through soar