Description
Key Responsibilities
- Monitor, investigate, and respond to security alerts and incidents using Exabeam SIEM and UEBA.
- Lead advanced incident investigations, including root cause analysis, containment, eradication, recovery, and post-incident reviews.
- Serve as the primary SOC point of contact for the customer and represent SOC operations in day-to-day engagements.
- Act as the Incident Responder and Commander during high-priority security incidents, coordinating response activities across multiple teams.
- Develop, tune, and optimize Exabeam correlation rules, behavioral analytics use cases, dashboards, and detection content.
- Conduct proactive threat hunting activities leveraging security telemetry, UEBA insights, and threat intelligence.
- Leverage Anomali threat intelligence to enrich investigations and improve detection effectiveness.
- Map detections and investigations to the MITRE ATT&CK framework.
- Collaborate with onshore and offshore SOC teams, as well as infrastructure, network, cloud, and application teams.
- Produce executive and technical incident reports, threat trend analysis, and operational metrics.
Required Skills & Experience
- Minimum 4 years of core SOC experience.
- Mandatory hands-on experience with Exabeam SIEM and UEBA.
- Strong experience in:
- Security Monitoring & Incident Response
- Threat Hunting
- Detection Engineering
- Security Event Correlation & Log Analysis
- Threat Intelligence Operations
- MITRE ATT&CK Framework
- IOC/IOA Analysis
- Root Cause Analysis