arrow Back

Associate Analyst

Cyber Defence Centre
|
Pune, India

By contacting us you agree with the storage and handling of your data by this website. Please view the terms of our policy here.

Job Description:

we are searching for an Associate Analyst who will be responsible for monitoring, reporting, and escalating events to our Analysts. The primary function of this position is to monitor the analytics tools and perform alert management and initial incident qualification. This role reports to the Cyber Defence Centre (CDC) Team Lead.

Responsibilities:

  • Acknowledge, analyse and validate incidents triggered from correlated events through SIEM solution
  • Acknowledge, analyse and validate incidents received through other reporting mechanisms such as email, phone calls, management directions, etc.
  • Collection of necessary logs that could help in the incident containment and security investigation
  • Escalate validated and confirmed incidents to Analyst
  • Undertake first stages of false positive and false negative analysis
  • Understand the structure and the meaning of logs from different log sources such as FW, IDS, Windows DC, Cisco appliances, AV and antimalware software, email security etc.
  • Understand the subject of EDR alarms
  • Open incidents in SecurityHQ (ITSM Platform) to report the alarms triggered or threats detected. Analyst should properly include for each incident on SecurityHQ all details related to the logs, alarms and other indicators identified in accordance with the intervention protocol of each client and the SLA.
  • Track and update incidents and requests based on client’s updates and analysis results
  • Properly log client requests and change requests in SecurityHQ
  • Report infrastructure issues to the SHQ support team.
  • Report false positive alarms from EDR and SIEM to L2 SOC analysts