Upgrade and maintenance of SIEM Infrastructure. Knowledge of Windows/Linux based servers basic management and command line tools.
Cyber incident and forensic investigation.
Logs analysis and co-relation of security events.
Self-motivated and quick learner and should be flexible in working 24*7 environment
Strong understanding of Google SIEM concepts (log analysis, threat detection, correlation rules, data ingestion, parsing, search).
Software & System Understanding: Deep understanding of cloud technology and software architectures, particularly within the GCP environment.
Strong understanding of SOAR concepts (security orchestration, automation, response, playbook design, integrations, case management).
Experience with Google SecOps SIEM/SOAR products is highly desirable.
Cloud Computing: Familiarity with cloud platforms and their core services (GCP knowledge is an advantage).
Providing technical assistance to users, both internal and external, through various channels
Communicating technical information clearly and concisely to users and stakeholders
Ensuring consistent and secure configurations across the cloud environment
Support with 24x7 operations (Rotational Shifts)
English language (verbal and written) Proficiency is must
" Support with 24x7 operations (Rotational Shifts)
Own and resolve technical cases end-to-end
Ensure accurate documentation.
Meet defined SLAs and quality benchmarks while handling customer communications."