Senior - Signature Development

3 - 5 years

4 - 7 Lacs

Posted:20 hours ago| Platform: Naukri logo

Apply

Work Mode

Hybrid

Job Type

Full Time

Job Description

KEY Capabilities

  • Experience in working with SIEM Solutions such as Splunk or Azure Sentinel.
  • Experience in working with any of Endpoint Detection and Response tools preferably Crowdstrike, Sentinel One or Microsoft Defender for Endpoint.
  • Expertise in SIEM and EDR content development with an eye towards behavior-based detection logic.
  • Strong background in host based and network-based behaviors.
  • Familiarity of Windows Event IDs and common application logs.
  • Knowledge in programming or scripting languages such as Batch Scripting, Python PowerShell, etc.
  • Experience in purple teaming activities.
  • Hands-on experience on threat Hunting for identification of interested events for content development.
  • Analyze and investigate broad range of threats or cyber activities occurring on daily basis.
  • Provide actionable insights to help identify, detect, prevent, and respond to potentially malicious activities.

Qualification and experience

  • Minimum of 3 to 7 years experience with in-depth host, network architecture knowledge that will translate over to effective content development.
  • Minimum of 3 years SOC experience.
  • An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors. 
  • Strong oral, written and listening skills are an essential component to effective consulting.
  • Ability to work at all layers of the OSI models, including being able to explain communication at any level is necessary.
  • Must have content development knowledge in Endpoint Detection and Response (Defender/CrowdStrike), SIEM (Splunk/Sentinel).
  • Must have knowledge of Windows and Linux basics including command and script interpreters, PowerShell, registries etc.
  • Troubleshoot EDR and SIEM platform and application issues, escalate and work with relevant teams to resolve issues.
  • Certifications in a core security related discipline will be an added advantage.
  • Certification in any one of the SIEM, EDR or Network Solutions such as Splunk, Azure Sentinel, Falcon Crowdstrike, SentinelOne will be an added advantage.

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now
EY logo
EY

Professional Services

London

RecommendedJobs for You

chennai, bengaluru, delhi / ncr

hyderabad, chennai, bengaluru

chennai, bengaluru, delhi / ncr