Flag job

Report

Technical Analyst - SIEM L1

Min Experience

2 years

Location

BANGALORE, Karnataka, India

JobType

full-time

About the job

Info This job is sourced from a job board

About the role

Roles & Responsibilities: 1. Handling alerts and incident on XDR platform 2. Alert & incident triage and analysis 3. Proactively investigating suspicious activities 4. Log all findings, actions taken, and escalations clearly in the XDR and ITSM platform 5. Execute predefined actions such as isolating blocking IPs or disabling user accounts, based on set protocols. 6. Adhere to established policies, procedures, and security practices. 7. Follow-up with tech team for incident closure 8. Participating in daily standup and review meeting 9. L1 Analyst has responsibility to closely track the incidents and support for closure. 10. Escalate more complex incidents to L2 analysts for deeper analysis. 11. Work & support on multiple cybersecurity tool (DLP, GRC, Cloudsec tool, DAM) 12. Handle XDR alerts and followup with customer team for agent updates Key Responsibilities: Security Monitoring & Incident Response Governance Define and maintain security monitoring, threat detection, and incident response policies and procedures.Establish and mature a threat intelligence program, incorporating tactical and strategic threat feeds.Align SOC operations with evolving business risk priorities and regulatory frameworks. Platform & Toolset Management Evaluate, implement, and enhance SIEM platforms, ensuring optimal log ingestion, correlation, and rule effectiveness.Assess and manage deployment of EDR, XDR, SOAR, and Threat Intelligence solutions.Maintain and update incident response playbooks and automation workflows.Ensure consistent platform hygiene and technology stack effectiveness across SOC tooling. SOC Operations & Threat Detection Oversee 24x7 monitoring of security events and alerts across enterprise assets.Lead and coordinate proactive threat hunting across networks, endpoints, and cloud.Manage and support forensic investigations to identify root cause and recovery paths.Govern use case development, log source onboarding, and alert/event triage processes. Regulatory Compliance & Incident Management Ensure timely and accurate incident reporting in compliance with RBI, CERT-In, and other authorities.Retain logs in accordance with regulatory data retention mandates.Enforce and monitor security baselines for endpoints, in line with internal and regulatory standards. Advanced Threat Management & Reporting Plan, conduct, and report on Red Teaming and Purple Teaming exercises to test detection and response capabilities.Participate in and contribute to the Risk Operations Committee (ROC) meetings and initiatives.Review and track SOC effectiveness through KPIs, metrics, and regular reporting dashboards.

About the company

IBM's greatest invention is the IBMer. We believe that through the application of intelligence, reason and science, we can improve business, society and the human condition, bringing the power of an open hybrid cloud and AI strategy to life for our clients and partners around the world. Restlessly reinventing since 1911, we are not only one of the largest corporate organizations in the world, we're also one of the biggest technology and consulting employers, with many of the Fortune 50 companies relying on the IBM Cloud to run their business. At IBM, we pride ourselves on being an early adopter of artificial intelligence, quantum computing and blockchain. Now it's time for you to join us on our journey to being a responsible technology innovator and a force for good in the world.

Skills

siem
xdr
incident response
threat detection
cybersecurity