Employer Active
Job Alert
You will be updated with latest job alerts via emailJob Alert
You will be updated with latest job alerts via emailSenior SOC Analyst (Level 3
Bangalore/Gurgaon India
AXA XL has an exciting opportunity for an experienced L3 Senior SOC analyst to join the Security Operations team supporting security incident investigations across the organisations global infrastructure and responding to escalations from the Level 1 and 2 SOC teams. The successful candidate will have a history of successfully managing complex and highseverity cyber security incidents.
DISCOVER your opportunity
What will your essential responsibilities include
Take full ownership of incidents escalated by Level 2 analysts.
Conduct complex investigations and provide advice to L2 SOC analysts.
Develop customized scripts and procedures to automate repetitive tasks and improve the efficiency of incident response activities.
Provide expert advice on incident remediation and recovery efforts.
Develop threat remediation strategies.
Perform proactive analysis of AXA XLs attack surface and advice on potential threats and attack vectors.
Review and provide feedback on security control capability gaps based on security intrusion trends.
Create and refine runbooks/playbooks for all alerts.
Onboard log sources and work on log issues.
Finetune EDR and other tooling to exclude noise and false positives.
Create and finetune content in SIEM correlation rules Dashboard and Reports.
Interact with SIEM EDR and other SOC tooling vendors (TAC Support) to remediate any issues with tooling.
Monitor API threat detection reporting and containments.
Demonstrate experience in conducting digital forensics investigations relating to incident detection and response.
Responsible for making decisions and identifying required actions. During highseverity security incidents you will advise the AXA XL Head of SOC CISO and CSO on appropriate containment eradication and remediation measures.
Provide an afterhours point of escalation for critical incidents.
Define the operational roadmap and key metrics for incident detection and response.
Collaborate with internal stakeholders to align on and implement security incident detection and response processes.
Develop SOC security incident policies and investigation procedures for use across multiple information systems and teams.
Conduct compliance monitoring and perform SOC/SIEM security control testing.
Analyze define and manage the delivery of new SIEM rules.
Conduct use case testing and modify or create as and when required.
Create new custom detection rules using KQL.
Design and implement SIEM and EDR enhancements and configurations.
Manage and represent the Security Operations team on ethical hack exercises.
You will report to the Head of SOC.
SHARE your talent
We are looking for someone who has these abilities and skills:
Required Skills and Abilities:
Good knowledge of Microsoft Defender and Microsoft Sentinel including developing complex KQL queries.
Experience in performing digital forensics investigations.
Experience in developing scripts (Python Powershell etc. quickly in reaction to incidents.
Demonstrate experience of good knowledge in information security principles applied to architecture networks & systems digital forensics security risk assessments and software development).
Good knowledge and understanding of technologies utilized in cyber security (SIEM SOAR Firewalls IAM IDS/IPS Antimalware End Point Protection Database Security Threat management/intelligence).
Actionable knowledge of MITRE ATT&CK framework.
Effective knowledge of exploitable vulnerabilities and remediation techniques.
Experience in automating manual processes for responding to security incidents.
Experience in threat intelligence and CERT/CSIRT activities.
Knowledge of current threat actor techniques.
Understanding of threat landscapes and threat modelling security threat and vulnerability management and security monitoring.
Awareness of tools and techniques used by attackers to enter corporate networks including common IT system flaws and vulnerabilities.
Desired Skills and Abilities:
Excellent troubleshooting and critical thinking skills.
Experience in SOC documentation development.
Demonstrated experience in communicating complex security concepts both verbally and in writing to a variety of audiences.
Must take ownership of tasks and demonstrate a high degree of autonomy to ensure completion.
Must be personable and foster good stakeholder and peer group working relationships.
Certifications such as CISSP GIAC CEH or other.
FIND your future
AXA XL the P&C and speciality risk division of AXA is known for solving complex risks. For midsized companies multinationals and even some inspirational individuals we dont just provide re/insurance we reinvent it.
How By combining a comprehensive and efficient capital platform datadriven insights leading technology and the best talent in an agile and inclusive workspace empowered to deliver top client service across all our lines of business property casualty professional financial lines and speciality.
With an innovative and flexible approach to risk solutions we partner with those who move the world forward.
Learn more at axaxl
AXA XL is committed to equal employment opportunity and will consider applicants regardless of gender sexual orientation age ethnicity and origins marital status religion disability or any other protected characteristic.
At AXA XL we know that an inclusive culture and a diverse workforce enable business growth and are critical to our success. Thats why we have made a strategic commitment to attract develop advance and retain the most diverse workforce possible and create an inclusive culture where everyone can bring their full selves to work and reach their highest potential. Its about helping one another and our business to move forward and succeed.
Learn more at axaxl/aboutus/inclusionanddiversity. AXA XL is an Equal Opportunity Employer.
Sustainability
At AXA XL Sustainability is integral to our business strategy. In an everchanging world AXA XL protects what matters most for our clients and communities. We know that sustainability is at the root of a more resilient future. Our 202326 Sustainability strategy called Roots of resilience focuses on protecting natural ecosystems addressing climate change and embedding sustainable practices across our operations.
Our Pillars:
For more information please see axaxl/sustainability.
Required Experience:
Senior IC
Full-Time