Cloud and Network Security Consultan
Bangalore, IN
IBM
For more than a century, IBM has been a global technology innovator, leading advances in AI, automation and hybrid cloud solutions that help businesses grow.Information and Data are some of the most important organizational assets in today’s businesses. As a Security Consultant, you will be a key advisor for IBM’s clients, analyzing business requirements to design and implement the best security solutions for their needs. You will apply your technical skills to find the balance between enabling and securing the client’s organization with the cognitive solutions that are making IBM the fastest growing enterprise security business in the world.
Your Role and Responsibilities
- EDR alert monitoring.
- Performing TI based and hypothesis driven threat hunting oriented to SIEM logs.
- Support the incident response team during major security incident with advance investigation skills.
- Closely work with SOC team and be responsible for incident detection, triage, analysis and response.
- Handle L2 and above level technical escalations from L1 Operations team and resolve within SLA.
- Finetune of existing use case of SIEM to reduce false positive.
- Perform and reviews tasks as identified in a daily task list.
- Report Generation and Trend Analysis.
- Walkthrough of the daily, weekly, and monthly SOC reports to the customer/stake holders.
- Ready to work in 24×7 rotational shift model including night shift.
- Identify the process and technology gaps and drive for closure.
- Explore different technologies available in the security industry.
- Analyse and tune threat monitoring dashboards.
- Coordination with internal customers for their security related problems and providing solutions.
- Create and manage various KEDBs the SOPs, runbooks, asset inventory with risk classification, critical application flow diagram, network flow diagram, privileged user list.
- Mentor and monitor L1 team members for their daily activities.
- Provide KT and required training to other team members.
Required Technical and Professional Expertise
Hands-on Experience on minimum 3 technologies
Assist in troubleshooting and problem solving a wide variety of client IT security related issues (Cisco FTD/Palo Alto/Checkpoint/Fortinet/Azure firewalls, IDS/IPS, VPN, proxy, Bluecoat/Forcepoint/Zscalar Web filtering).
Mentor Tier 1 staff on event handling & response
Manage day to day firewall operations, implementing firewall rule requests, configuration changes.
Continually improve upon skills and ability to learn new technologies
Incorporate and follow all change management processes and procedures as outlined by the customer.
Participate in security and vulnerability risk assessments of the enterprise firewall environment.
Contribute to L2/L3 SOPs/Runbook/KEDB in keeping process & documentation up to date.
Contribute to request/incident/change management improvement process
Ready to learn new technologies through internal trainings
Ready to work 24*7
- Experience on firewall rules and data flow traffic in firewalls.
- Experience on clustering and high availability.
- Should have good technical expertise in managing PaloAlto, Fortinet, Cisco, and Bluecoat.
- Should have good technical knowledge and hands on in cloud security solutions (AWS, Azure) like Microsoft cloud native security, PaloAlto, Zscalar
- Experience in configuration and implementation of VPN across various vendor perimeter devices.
- Experience in routing technologies.
- Skilled in analyzing and monitoring network security solutions.
- Should possess core understanding of web filtering gateways like BlueCoat, Zscaler or PaloAlto.
- Install firmware and patch updates
- Install policy for allowing/restricting access to web URL’s
- Setting up rules for category wise access requests
- Managing whitelist and blacklist files
- Monitoring web access for users/source
- Configuring and managing reverse proxy
- Extracting and analyzing web access reports
- Linux Basic knowledge, Advanced preferable.
- Basic Scripting knowledge in Python or shell scripting
Preferred Technical and Professional Expertise
- Certifications – CCNA, CCSP or PCNSE or FCNSE and AZ-500
Key Job Details
Role:Cloud and Network Security Consultan Location:Bangalore, IN Category:Consulting Employment Type:Full-Time Travel Required:No Travel Contract Type:Regular Company:(0063) IBM India Private Limited Req ID:713135BR
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: AWS Azure CCSP Cloud EDR Firewalls IDS Incident response IPS Linux Monitoring Network security Python Risk assessment Scripting SIEM SOC VPN
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.