Security Consultant - UEBA Platform Engineering & Ops

3 - 5 years

11 - 16 Lacs

Posted:1 week ago| Platform: Naukri logo

Apply

Work Mode

Work from Office

Job Type

Full Time

Job Description


A UEBA (User and Entity Behavior Analytics) Administrator is a cybersecurity professional responsible for deploying, configuring, maintaining, and optimizing UEBA solutions to detect and respond to anomalous user and entity behavior within an organization's network. This role is crucial in identifying insider threats, compromised accounts, and sophisticated attacks that might bypass traditional security measures.-------------------------Key ResponsibilitiesThe UEBA Administrator's responsibilities:*Deployment and Configuration:*Installing and setting up UEBA platforms and related components.*Integrating UEBA solutions with various data sources (e.g., SIEM, Active Directory, network devices, applications, cloud services, endpoint logs) to ensure comprehensive data ingestion.*Defining and configuring behavioral baselines for users and entities, utilizing machine learning algorithms.*Monitoring and Analysis:*Continuously monitoring UEBA dashboards and alerts for deviations from established baselines.*Analyzing anomalous activities to determine their risk level and potential impact.*Investigating security incidents triggered by UEBA alerts, collaborating with SOC teams and other security personnel.*Performing threat hunting activities using UEBA insights to proactively identify hidden threats.*Rule and Policy Management:*Developing, refining, and implementing correlation rules and policies within the UEBA platform to enhance threat detection accuracy.*Tuning the system to minimize false positives and ensure high-fidelity alerts.*Automating response actions where appropriate, such as locking accounts or blocking access.*System Maintenance and Optimization:*Performing regular health checks, upgrades, and patching of the UEBA infrastructure.*Optimizing the performance and efficiency of the UEBA solution.*Documenting configurations, procedures, and incident response playbooks related to UEBA.*Reporting and Compliance:*Generating reports on user and entity behavior, detected anomalies, and security posture.*Assisting with compliance requirements by providing data and insights from UEBA.* Staying updated with the latest threat landscape and UEBA capabilities.------------------- Required education Bachelor's Degree Preferred education Bachelor's Degree Required technical and professional expertise ------Required Skills and Qualifications*Technical Expertise:*Strong understanding of UEBA conceptsHow machine learning and behavioral analytics are applied to security.*Proficiency with UEBA platformsExperience with leading UEBA solutions (e.g., Gurucul UEBA, Splunk UEBA, Exabeam, Fortra, Microsoft Sentinel UEBA, IBM QRadar UEBA).*Networking KnowledgeUnderstanding of network protocols, traffic analysis, and common attack vectors.*Operating SystemsFamiliarity with Windows, Linux, and other relevant operating systems.*Security Information and Event Management (SIEM)Experience with SIEM tools and their integration with UEBA.*Data AnalysisAbility to work with large datasets, perform data correlation, and extract meaningful insights.*Scripting/AutomationKnowledge of scripting languages (e.g., Python, PowerShell) for automation and data manipulation is a plus.*Cloud SecurityUnderstanding of cloud environments and their unique security challenges if applicable.*Analytical Skills:
  • *Critical ThinkingAbility to analyze complex data and identify subtle behavioral anomalies.
    *Problem-SolvingAptitude for troubleshooting and resolving issues related to UEBA systems and security incidents.*Attention to DetailMeticulous approach to configuring systems and investigating alerts.*Soft Skills:
  • *CommunicationExcellent written and verbal communication skills to articulate technical concepts and findings to both technical and non-technical stakeholders.
    *TeamworkAbility to collaborate effectively with SOC analysts, incident response teams, and other IT departments.*Continuous LearningEagerness to stay abreast of evolving cybersecurity threats and technologies.*Qualifications:*Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field. Preferred technical and professional experience 3-5 yrs exp in managing Gurucul UEBA Platform Administration & OpsRelevant industry certifications (e.g., CompTIA Security+, Certified Ethical Hacker (CEH), GSEC, vendor-specific UEBA certifications) are highly advantageous. Proven experience in a security operations center (SOC) or a similar cybersecurity role.
  • Mock Interview

    Practice Video Interview with JobPe AI

    Start Python Interview
    cta

    Start Your Job Search Today

    Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

    Job Application AI Bot

    Job Application AI Bot

    Apply to 20+ Portals in one click

    Download Now

    Download the Mobile App

    Instantly access job listings, apply easily, and track applications.

    coding practice

    Enhance Your Python Skills

    Practice Python coding challenges to boost your skills

    Start Practicing Python Now
    IBM logo
    IBM

    Information Technology

    Armonk

    RecommendedJobs for You