Global SOC Engineer

LTIMindtree 

📍 London Area, United Kingdom 🇬🇧

full-time
mid-level
Expired
Posted —
This job posting has expired View All Embedded Systems Engineer Jobs

Key Skills

securityscriptingAPImonitoringForensics

Industry

Security & SurveillanceAerospace

Job Description

Role: Global SOC Engineer

  • Skills
  • Experience with security incident management and network monitoring in medium to large organizations
  • General Information Security experience CISSP preferred
  • Strong communication skills and experience working in the enterprise
  • Strong familiarity with security technologies in general both at the host and network level
  • Knowledge of Palo Alto Networks products
  • Working knowledge of Splunk, Splunk Enterprise Security
  • Scripting experience and experience developing or integrating of security tools using APIs
  • Experience with Forensic Analysis EnCase or similar is a plus
  • Responsibilities
  • The role will lead the day-to-day management of the Global Security Operations team specifically in incident detection and response with the Regional Teams across the Client Group Business Units
  • The role will lead each of the Business Units in running Security Incident Response Drills and Table Top Exercises
  • The role will be the main point of escalation for any security detections from Crowdstrike and Vectra
  • The role is pivotal in coordination management escalation and reporting of security related matters as well as providing evidence for ISO27001 and SOC2 audits
  • The role is responsible for installing configuring monitoring of EDR and Netksope agents across all of Business Units globally
  • The role will be managing Vendors represent the Global SOC in QBRs highlight gaps to vendors for improvement
  • Manage and maintain all Blue Team playbooks and ensure Crowdstrike Fusion SOAR automations are uptodate and operational
  • The role requires a knowledge in running scripts and workflows eg python powerautomate to run daily operational tasks including health checks threat hunting threat detection
  • Maintain and ensure that all Security Tools are fully integrated and feeding logs into NextGen SIEM
  • Perform Threat Hunting using NextGen SIEM able to find specific logs using Crowdstrike Query Language and create Fusion Workflows to detect IOCs notify teams for TTPs and apply automated remediations
  • Perform daily health checks of all Security Tools ensuring they all are operational