Actively monitoring, analysing & escalating SIEM alerts based on correlation rules,
Email protection alerts & malware analysis,
Provide inputs for proactive content fine tuning & use case enablement,
Active threat hunting on network flow, user behaviour & threat intelligence,
Phishing email analysis for MFs,
Raising incidents in Pastebin inte
Should be familiar with Domain Knowledge (Cyber Security), Threat Hunting, SIEM- Azure Sentinel, SIEM - (RSA / Splunk / LogRhythm), Python Scripting, Windows Active Directory, Operating systems and servers.
Ability to Triage and assignment Incident Handling.
Ability to Follow Playbooks instructions- Incident Response Playbooks
Ability to Comprehend Logs (HTTP, SMTP, Network) (Under guidance)
Understand and imbibe current SOC process
Perform quality assessment on SOC operations being performed as per existing process
Record and deviations identified into tracking tool(s)/spreadsheets
Perform follow-ups with respective error owners to mitigate process deviations
Identify process deviations, Summarize and generate trends, patterns into process deviations / errors observed.
Perform RCA into observed errors / trends and generate recommendations for process improvement
Generate personnel specific recommendations for performance enhancement
Contribute in overseeing quality assessment process for multiple SOC verticals
In-line alignment with SOC operations for quick-detection / prevention of process deviations
Support as QA touchpoint in critical cyber incidents to enhance quality of service
Assessment of investigation report with assertions, evidences and recommended actions
Qualifications
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
BE/B.Tech/Post-Grad/ Graduate or Postgraduate in any other discipline
0-2 years of relevant experience.
Candidates should be okay to work in rotational shifts.
Good to have - Certifications - CSA (Certified SoC Analyst), CISM and CCSP, Certifications from Microsoft Azure Suite
Candidates having SOC experience would be preferred
Well versed in Microsoft productivity tools such as Word, PowerPoint and Excel
An understanding of concepts of analytics and should be able to generate trends, drill downs, and various graphical representations
Windows / Azure / AWS infrastructure knowledge will have added advantage
Experience in Windows security tools like Defender for office, Defender for identity, Sentinel and other Microsoft security tools will have added advantage
Excellent written and oral communication skills
Equal employment opportunity information
KPMG India has a policy of providing equal opportunity for all applicants and employees regardless of their color, caste, religion, age, sex/gender, national origin, citizenship, sexual orientation, gender identity or expression, disability or other legally protected status. KPMG India values diversity and we request you to submit the details below to support us in our endeavor for diversity. Providing the below information is voluntary and refusal to submit such information will not be prejudicial to you .
About KPMG Assurance and Consulting Services LLP
Verified company details for this employer are not available yet.