Job Description
AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digital transformation. AtAHEAD, we prioritize creating a culture of belonging,where all perspectives and voices are represented, valued, respected, and heard. We create spaces to empower everyone to speak up, make change, and drive the culture at AHEAD. We are an equal opportunity employer,anddo not discriminatebased onan individual's race, national origin, color, gender, gender identity, gender expression, sexual orientation, religion, age, disability, maritalstatus,or any other protected characteristic under applicable law, whether actual or perceived. SOC Analysts at AHEAD monitor customer environments and perform Incident Detection, Validation, and Incident Reporting. SOC Analysts are the frontline of SOC and are customer-facing representatives. SOC Analysts are responsible for triaging events, incidents, and reporting validated incidents to the customer for incident response. Incumbents will possess strong technical and analytical skills while providing accurate analysis of security related problems. They have a well-rounded networking background and are responsible for performing troubleshooting of customer issues. This individual is user focused and works to resolve client needs in a timely manner. These needs may involve resolving hardware/software failures, investigating, and responding to security threats, and making change request to the security policy of company devices.The SOC Analystis expected to monitor security feeds streaming from client servers, network devices, and end user workstations, operate and maintain network security equipmentat client locations. The Analystis expected to be familiar with a wide range of security tools and understand basic security fundamentals. TheAnalystwill perform information security event analysis and must possess knowledge of operating systems, TCP/IP networking, network attacks, attack signatures, defense countermeasures, vulnerability management, and log analysis.
Roles & Responsibilities:Monitor and analyze network traffic and alertsInvestigate intrusion attempts and perform in-depth analysis of exploitsProvide network intrusion detection expertise to support timely and effective decision making of when to declare an incidentConduct proactive threat researchReview security events that are populated in a Security Information and Event Management (SIEM) systemTuning of rules, filters, and policies for detection-related security technologies to improve accuracy and visibilityData mining of log sources to uncover and investigate anomalous activity, along with related items of interestIndependently follow procedures to contain, analyze, and eradicate malicious activityDocument all activities during an incident and provide leadership with status updates during the life cycle of the incidentIncident management, response, and reportingProvide information regarding intrusion events, security incidents, and other threat indications and warning information to the clientTrack trends, statistics, and key figures for each assigned clientAssist with the development of processes and procedures to improve incident response times, analysis of incident, and overall SOC functionsReportingIncident reportsSecurity status reportsClient-facing security meetingsPosition :Incident handling/response experienceWorking knowledge of common operating systems (Windows, Linux, etc.) and basic endpoint security principlesUnderstanding ofanda strong desire to learn common security technologies (IDS, Firewall, SIEM, etc.)The ability to think creatively to find elegant solutions to complex problemsExcellent verbal and written communication skillsThe desire to work both independently and collaboratively with a larger teamA willingness to be challenged along with a strong appetite for learning8-10years of experience in Information Security, Incident Response, etc. (or related field)Hands-on experience with common security technologies (IDS, Firewall, SIEM, etc.)Knowledge of common security analysis tools & techniquesUnderstanding of common security threats, attack vectors, vulnerabilities and exploitsKnowledge of regular expressionsEducation:BachelorsDegree in Computer Science, Information Security or related/equivalent educational or work experienceOne or more of the following certificationsCISSP, GCIA, Security+, CEH, ACSEJob Classification
Industry: IT Services & Consulting
Functional Area / Department: IT & Information Security
Role Category: IT Security
Role: Security Engineer / Analyst
Employement Type: Full time
Contact Details:
Company: Ahead
Location(s): Noida, Gurugram
Keyskills:
tcp
ip networking
vulnerability management
tcp ip networking
log analysis
security analysis
network security
soc
ip
ceh
information security
networking
intrusion detection
siem
incident response
firewall
incident management
linux
ids