Role :
Security Ops Center Associate
Location :
Work From Office
Job description
ECI: Leading global provider of managed services, cybersecurity, and business transformation for mid-market financial services. Serving over 1,000 customers with $3 trillion AUM, ECI offers stability, security, and enhanced business performance.
Responsibilities:
- Analyze and respond to network security events.
- Conduct threat actor-based investigations.
- Develop new detection methodologies.
- Provide 1st level support for incident response and monitoring.
- Proactively monitor and respond to emerging threats.
Explore more new job openings
What you will do
– **Proactive Monitoring**: Monitor and respond to known and emerging network threats.
– **Threat Investigation**: Conduct threat actor-based investigations using SIEM, EDR, and Email gateway.
– **Detection Methodology**: Develop and direct new detection methodologies.
– **Incident Response**: Provide 1st level support for incident response and monitoring.
– **Event Triage**: Investigate and triage security events, escalating as necessary.
– **Intrusion Analysis**: Identify and differentiate between false positives and actual intrusion attempts.
– **Documentation**: Document and present findings on security incidents and investigations.
– **Team Collaboration**: Work with the team to mitigate and counteract threats.
– **Email Analysis**: Perform email analysis and categorize with verdicts.
– **Stay Informed**: Keep up-to-date with the latest security trends and best practices.
– **Effective Communication**: Communicate with business representatives, technology specialists, customers, and vendors.
– **Knowledge Improvement**: Continuously enhance knowledge of information security and identify/prevent phishing attempts.
Education Requirement
- Minimum 0 – 1 year of experience in the IT industry, preferably working in a SOC environment.
- Bachelors in Computer science/IT/Electronics Engineering, M.C.A. or equivalent University degree.
Good to have skills
- Certifications: CCNA, CEH, CHFI.
- Knowledge on SIEM, IDS/IPS, Firewall, VPN, EDR, AV and other security products.
- Knowledge on TCP/IP network traffic and event log analysis.