Job Title: Cybersecurity Sr. Specialist Incident ResponseRole Overview: The Cybersecurity Specialist is responsible for the Incident Response Activity. This role will help develop innovative andEffective procedures for the Security Operations Center to enhance response time, coordination, and incident responseoperations, and built a world-class team of Cyber Security Incident Response. Train staff on security operations concepts,develop incident response management process, write correlations, and integrate intelligence data into monitoring andoperations activities.Roles & Responsibilities:This person will support the Information Security department's goals and objectives by addressing escalations, and theevaluation of technology controls providing key insight and research in new threats, vulnerabilities, and mitigationtechniques. In this role, they will take the lead in proposing solutions to improve or reduce risk exposure from the overallthreat landscape and improve the resilience and readiness of security technologies and processes, which ensure theconfidentiality, integrity, and availability of the organization's assets, information, data, and IT services in an efficientmanner. Develop and execute security incident response plans and cyber forensic investigations to investigate allreported security incidents. Develop comprehensive incident reports and investigation summaries. Develop and collect intelligence to proactively detect and identify high-confidence threats to the brand, serviceinfrastructure, and enterprise users and systems. Responsible for analyzing/validating security control requirements and tuning, defining the mitigation rules,scripting, and performing changes or mitigating attacks, and assisting with troubleshooting support related toany issues that may arise from security detection or protection technologies. Assist with reviewing existing tools, applications, and processes to help strengthen and optimize current securitycapabilities, as well as identifying any gaps or technical solutions to further enhance the team's effectiveness. Communicate problems and solutions verbally and in written form to peers and management. Compliance and governance: help achieve compliance, identify compliance initiatives, and promote appropriatesecurity policies. Lead analysis and review security events for anomalous activity, collaborate with respective peer groups to takeappropriate action to safeguard company information assets against current and foreseen threats. Lead the exploration of practical security solutions to address emerging threats and compliance requirements,including design and implementation of recommended solutions.Preferred Experience/Skills: 6+ years' experience with Incident Response Experience in a 24x7 global enterprise, preferably in the healthcare industry. SANS GIAC certifications Experience managing or maintaining malware analysis sandboxes. Knowledge of malware analysis tools Python and/or PowerShell scripting Knowledge of LogRhythm products or other SIEM tools Excellent communication and interpersonal skillsIncident Response2 Revised: 8/2022 Understanding of the business and the ability to assess and address risk without negatively impacting thebusiness. Ability to identify and analyze malicious code. In-depth understanding of Windows operating systems Ability to evaluate exploit code in relation to existing security controls. Strong knowledge of networking technologies (TCP/IP, HTTP, SMTP, etc.) Strong knowledge of web application vulnerabilities and solutions Strong knowledge of Windows operating systems Strong knowledge of the functions of various security infrastructure, including firewalls,Intrusion Prevention Systems, Proxy Servers, Security Event Managers, VPNs General knowledge of network and systems forensics. In-depth knowledge of incident response processes and procedures. Ability to provide 24-hour on-call support on a rotating basis.Work Location: Bangalore/ Hyderabad;