Jobs
>
Hyderabad

    Technical Specialist – MS, SOC - hyderabad, India - NTT DATA

    NTT DATA
    NTT Data background
    Description

    Job Description

    NTT is a leading global IT solutions and services organisation that brings together people, data and things to create a better and more sustainable future.

    In today's 'iNTTerconnected' world, connections matter more now than ever. By bringing together talented people, world-class technology partners and emerging innovators, we help our clients solve some of the world's most significant technological, business and societal challenges.

    With people at the heart of our success, NTT is committed to attracting and growing the best talent and providing an environment where everyone feels they can belong and their contribution matters.

    Want to be a part of our team?

    Provides technical support to field engineers, technicians, and product support personnel who are diagnosing, troubleshooting, repairing, and debugging complex electro/mechanical equipment, computer systems, complex software, or networked and/or wireless systems.
    Responds to situations where first-line product support has failed to isolate or fix problems in malfunctioning equipment or software. Reports design, reliability, and maintenance problems or bugs to design engineering/software engineering. May be involved in customer installation and training.
    Provides support to customers/users where the product is highly technical or sophisticated in nature.

    Working at NTT

    The SOC L3 is responsible for providing service to clients by proactively identifying and resolving technical incidents and problems. Through preemptive service incident and resolution activities, as well as product reviews, operational improvements, operational practices, and quality assurance this role will maintain a high level of service to clients. Their primary objective is to ensure zero missed service level agreement (SLA) conditions. The SOC L3 is responsible for managing tickets of low to high complexity.

    Key Roles and Responsibilities:

    NG SIEM (SIEM+SOAR+UEBA) Tool Overall Administration,
    Management, Backup & Archival, Troubleshooting
     Upgrade/Update/Patching of NG SIEM Solution
     Monitor NG SIEM Console & Dashboards and provide response &
    support to remote SOC team for Incidents.
     Support the day to day operation of deployed NG SIEM.
     Perform initial analysis for known issues and provide the
    appropriate recommendations for closure.
     Monitor & Reporting of system components health and take
    necessary action in case of any observed issue.
     Provide notification and communication with Incident
    management and respective application team upon threat
    detection.
     Perform analysis on the reported incidents, determine the root
    cause, and recommend the appropriate solution.
     Integration of NG SIEM with IS infrastructure (Existing/Future) but
    not limited to like IPS, WAF, Patch Management, Firewall, Anti-APT
    solution, Antivirus, EDR, AD, ERP, DLP, VMT, Exchange, SharePoint,
    Network Devices, Web Services, Custom applications etc. & also on
    respective version upgrade(s)
     Develop appropriate use cases/playbooks/models/reports and
    alerts & develop custom parsers/connectors for integrating logs
    wherever necessary or required.
     Integration of SIEM/SOAR/UEBA Tool with security/non-security
    solutions based on requirement & architecture and develop/modify
    appropriate use cases/rules, playbooks/models, reports and alerts.

    Use and apply learnings from incident and provide
    recommendation for standardizing the NG SIEM Solution.
     Reduction of False Positives by fine tuning existing correlation
    rules/configuration/playbooks/models
     Automation with continuous improvements, Reduction in MTTR,
    MTTD
     Develop and implement processes for interfacing with operational
    teams and other supporting teams.
     Ensure the NG SIEM integration is intact among the Client SOC
    solutions, other assets
     Design, create and customize the dashboards as per the client
    requirements.
     Ensure the necessary client SOC documents like operating
    procedures, configuration management, Low Level Design etc. are
    up to date with the changes made in their respective areas.
     Automating Day to Day Tasks related with NG SIEM Operations (but
    not limited to)
     Above is illustrative list of general activities. All Technology specific
    activities Related to NG SIEM to be carried out.
     Use and apply learnings from incident and provide
    recommendation for standardizing the NGSIEM Solution.
     Ensure the SIEM integration is intact among the SOC
    solutions, other assets
     Design, create and customize the dashboards/reports as per the
    client requirements.
     Support on boarding and maintenance of a wide variety of data
    sources to include various OS, appliance, and application logs.
    Create Custom queries, custom dashboards, and visualizations
     Create and manage NG SIEM knowledge objects to include apps,
    dashboards, saved and scheduled searches and alerts.
     Support access requests and modifications and permissions
     Support troubleshooting and remediation of issues as they arise
    with data ingestion and NG SIEM infrastructure
     Work on Improvement of overall posture of NG SIEM deployment
    to achieve Best return on investment.
     Monitor & report on cyber threats and suggest any changes needed
    to protect the organization in SIEM, Leading End-to-End
    Implementation of the suggested changes.
     Should have a very good understanding on MITRE attack & NIST
    framework.

    Threat Hunting Requirements

    1. Use algorithms and tools to actively hunt of attacks in large volume
    of data and create alerts that are passed on to analysts.
    2. Define, develop, implement, update and maintain Hunting
    Framework which contains: Create Strategic Hunt Missions which
    are objective based to identify malicious activity that has not
    triggered an alert. Search for Indicators of Compromise received
    from Threat Intelligence and Analytics
    3. Create knowledge base of IOCs
    4. The service should able to detect threats from various attacks
    vectors such as malware, web application attacks, network attacks,
    watering hole attacks, DNS attacks, insider threat, and data
    exfiltration but not limited to. List the detection use cases which can
    detect above attacks using pre-built machine learning techniques
    and analytical models.
    5. Analytics using machine learning techniques should use multiple
    sources to identify malicious activity. A minimum the following
    sources should be used but not limited to:
    IPS/IDS, Proxy, FW, WAF, Anti APT, EDR, AV, Internet/Mail gateway,
    Windows & Linux logs, DNS.
    6. Bidder should have analytical models to detect different stages of
    Cyber Kill chain.
    7. Network Threat Hunting should leverage existing network sources
    for better detection of advanced attacks. Network sources should
    include Net flow, Proxy, DNS, IPS, VPN, Firewall, WAF,
    AD/Windows, Email logs etc.
    8. Network threat hunting should use AI on network sources and
    enable hunting for attacks including but not limited to Lateral
    Movement, Malware Beaconing, Data Exfiltration, Watering Hole,
    Targeted network attacks, Dynamic DNS attacks
    9. The service must be capable of identifying suspicious or hitherto
    undiscovered communication patterns to uncover hidden,
    advanced threats missed by automated, preventative and detective
    controls & detect suspicious trends. Service must support detection
    of newly discovered pattern in future.
    10. The service should identify network traffic from potentially risky
    applications (e.g. file sharing, peer-to-peer, etc.)

    Skills Summary

    Automation Tools, Cloud Security, Firewalls, Local Area Network (LAN), Palo Alto Networks Prisma Access Secure Access Service Edge (SASE), Security Technologies, TCP/IP Networking, Threat Management

    What will make you a good fit for the role?

    Remote Type:

    Equal Opportunity Employer

    NTT is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, color, sex, religion, national origin, disability, pregnancy, marital status, sexual orientation, gender reassignment, veteran status, or other protected category

    Join our growing global team and accelerate your career with us. Apply today.

    A career at NTT means:

  • Being part of a global pioneer – where you gain exposure to our Fortune 500 clients and world-leading global technology partners and work with a network of over 40,000 smart and diverse colleagues across 57 countries, delivering services in over 200 countries.
  • Being at the forefront of cutting-edge technology – backed with a 150-year heritage of using technology for good. With 40% of the world's internet traffic running on our network and where Emoji were first invented, you can be proud of the group's many new 'firsts'.
  • Making a difference – by doing meaningful work that helps to shape the future for our clients, and across industries and communities around the world.
  • Being your best self – in a progressive 'Connected Working' environment that promotes flexibility, connection and wellbeing. Where diversity and different perspectives are embraced to ensure equal opportunities for all.
  • Having ongoing opportunities to own and develop your career – with a personal and professional development plan and access to the broadest learning offerings in the industry.
  • Apply from local Career site Apply from local Career site Back to search results


  • NTT hyderabad, India Full time

    JOB DESCRIPTION NTT is a leading global IT solutions and services organisation that brings together people, data and things to create a better and more sustainable future. · In today's 'iNTTerconnected' world, connections matter more now than ever. By bringing together talented ...


  • NTT Hyderabad, India Full time

    NTT is a leading global IT solutions and services organisation that brings together people, data and things to create a better and more sustainable future. · In today's 'iNTTerconnected' world, connections matter more now than ever. By bringing together talented people, world-cla ...


  • UpMan Placements Hyderabad, India

    Job Location- Hyderabad - Remote, India- Experience (in Years Job Type- Full Time**Job Description**: · Role: Java with Cloud Security · Location: Remote · **Job Description**: · - BS/MS in Computer Science/Engineering with 8 years or equivalent experience · - Be a self-starter, ...

  • Leading IT Company

    SOC Analyst

    2 days ago


    Leading IT Company Hyderabad, India

    Crystal Solutions Ltd. is a leading International Recruitment Service provider for more than 30 years. We are hiring XSOAR / SIEM Admin - L2 for an IT Company in Hyderabad. Details of the requirement is as stated below. · Designation: XSOAR Admin L2 · Experience: 4 - 6 Yrs · Loca ...

  • Zigsaw

    Emulation Engineer

    2 days ago


    Zigsaw hyderabad, India

    JobDescription Experience withbringing up debugging and verification inEmulationZebu PCI PCIe DDR SATA USBAXI I2C ARM SOC Architecture FPGA emulation mode PowerVerification · Good understanding of any StandardEmulator (Palladium Veloce Zebu) · Exposure toworking with any of A ...

  • Leading IT Company

    SOC Analyst

    2 days ago


    Leading IT Company hyderabad, India

    Crystal Solutions Ltd. is a leading International Recruitment Service provider for more than 30 years. We are hiring XSOAR / SIEM Admin - L2 for an IT Company in Hyderabad. Details of the requirement is as stated below. · Designation: XSOAR Admin L2 · Experience: 4 - 6 Yrs · L ...


  • Quest Diagnostics Hyderabad, India

    Senior IT Security Assurance and Audit Specialist · SUMMARY : · Quest is seeking a motivated self-starter with excellent interpersonal, communication, and presentation skill to join the IT Security Risk and Assurance team to work with internal and external customers to address IT ...


  • Demandbase Hyderabad, India

    · About the Role: · Demandbase is seeking an experienced InfoSec / Customer Trust Specialist to join our Product Security team. In this role, you will be responsible for building & maintaining trust with our customers by communicating information about our security, privacy, and ...


  • NVIDIA Hyderabad, India

    We are now looking for a Manager of Functional Safety Tools · At NVIDIA, we are building the system, hardware, and software technology which enables autonomous driving. Our safety engineering team is currently seeking a · Manager of Functional Safety Tools · to guide the developm ...


  • Demandbase Hyderabad, India

    About the Role: · Demandbase is seeking an experienced InfoSec / Customer Trust Specialist to join our Product Security team. In this role, you will be responsible for building & maintaining trust with our customers by communicating information about our security, privacy, and co ...


  • Model N Hyderabad, India Regular Full time

    Job Summary The People Operations Specialist plays a vital role in our centralized People Operations function. Responsibilities encompass maintaining comprehensive knowledge of HR service areas and providing tier 1 essential assistance to employees on HR-related matters. This inc ...


  • PepsiCo Hyderabad, India Full time

    Overview The Cloud Security Specialist will be part of PepsiCo's Cloud Acceleration and Value Office (CAVO) and will be driving Cloud security initiatives & improvements. This is a role to develop cloud security model to enable our digital transformation. This role will help to ...