SOC Detection Lead
Bangalore (Airbus), India
Airbus
Airbus designs, manufactures and delivers industry-leading commercial aircraft, helicopters, military transports, satellites, launchers and more.Job Description:
Description:
SOC Detection Lead will be part of the Digital function, which is responsible for Airbus information management capabilities and is continuously building, operating new business and platforms, services adoption of new technologies, automation, digital native skills and agile ways of working to accelerate our digitalization journey. Digital is about making the benefits of digital technologies available to Airbus so we can bring value to market much faster, while retaining quality and scale.
Your role is to lead the team of detection engineers and guide them with their research and suggest security detection scenarios and propose automations to enhance SOC detection and response capabilities . You will also be responsible to develop a roadmap and strategies for threat detection, investigation and response along with producing management information, including reports and KPIs, create and enhance internal processes and procedures. Your role is key as you contribute to the overall performance and success of the Security Operations Centre.
Challenges are numerous and exciting!
What is the Airbus Detect and Response team doing?
Security threats have increased drastically in the last few years and organizations are facing an increasingly complex threat landscape. Airbus digitalization is bringing many opportunities but they come with new risks. Therefore, the main mission of Detection & Response (D&R) is to identify the threats and detect security incidents that target Airbus company-wide, and propose adapted security response. D&R teams are supporting Airbus businesses and ensuring their protection against cyber threats.
Security is not an option, be part of it!
The SOC Mission:
Monitoring, detection, and analysis of potential intrusions in real time and through historical trending on security-relevant data sources
Response to confirmed incidents, by directing use of timely and appropriate countermeasures
Providing situational awareness and reporting on cybersecurity status, incidents
Qualification & Experience:
We seek out curious minds! We value attention to detail! And we care deeply about outcomes!
We’re looking for passionate people, who are eager to learn, willing to share, and establishing innovative ways of working and influencing culture change
Bachelor degree in Computer Science, Engineering, or related field
Masters in Information Security would be preferred
6 to 10+ years of relevant experience as a Detection and Automation Engineer or SOC L2/L3 Analyst
Information Security and/or Information Technology industry certification (CASP+, SANS-GIAC, OSCP, CISSP or equivalent) will be preferred
Experience and working knowledge of building detection and investigating the threat scenarios for platforms such as Windows, Network, Unix/Linux, Cloud(AWS / GCP), Containers etc.
Good understanding & knowledge of automation, scripting using Python and JavaScript is required
Must have knowledge of network and web technology, encryption, virtual private networks, internet / extranet security, cloud computing, firewalls, remote access and overall security management
Knowledge & experience in Splunk Enterprise Security (any certification appreciated) including knowledge in log management, Splunk application and search development (SPL), SOAR technology
Knowledge in SOC referential such as Sigma, STIX/TAXII, MITRE ATT&CK
Proven ability to prioritize workload, meet deadlines, and utilize time effectively
Good interpersonal and communication skills, works effectively as a team player
French language knowledge will be an added advantage
Responsibilities
Research & Security Monitoring:
Research, understand latest threats targeting various operating systems, platforms and applications to build & fine-tune SOC detections
Contribute towards defining log configurations and data normalization of various log sources for its processing in security detections
Develop detection use cases and dashboards to identify patterns and anomalies in network traffic, system logs, and application data that could indicate security incidents
Perform adversary emulation to mimic an existing known threat actors / APT groups on a dedicated testing infrastructure to proactively evaluate the efficacy and gaps in our security controls
Develop detection specific test case and regression tests to validate functionality of the implemented use cases
Plan and conduct workshops between Detection Engineers, SOC Analysts and Business Stakeholder to improve the overall security detection posture of Airbus
Ensure the SIEM platform & tool is configured with accurate use case requirements and configuration details including its supporting SOC processes
Automation & Incident Response:
Propose and develop investigative automations to help incident response team in quick and efficient decision making
Extend support towards purple teaming activities along with SOC incident response team to identify gaps and improve the overall detection and response capabilities
Participate in supporting the SOC incident response team in investigation and analysis of potential security incidents and vulnerabilities
Collaboration and Documentation:
Collaborate with SOC Product Manager to develop detection, investigation and remediation strategies and roadmap
Work closely with other security teams (Security architects, Red team, Application security & others) to improve threat detection and response strategies
Develop and produce detailed documentation for each SOC use case including the end to end full lifecycle of delivery of the use case and roles and responsibility within the SOC team to deliver and fulfil the use case requirement
Provide technical support in the areas of vulnerability, risk assessment, and security implementation
Engage with Head of SOC, Product Manager and Scrum Master to prioritize use case implementations
Continuous Learning and Development:
Participate in Security threat and monitoring forums to learn and keep abreast of the latest security trends, threats, and vulnerabilities, continually building knowledge in the cyber threat landscapes and good practices
Participate in workshops, training, certifications and security conferences to enhance skills in cyber detection and response
Benefits
You will be part of a truly international team
Travel opportunities (domestic and international)
Competitive remuneration, bonus and incentives
Good work / life balance and career growth opportunities
Training and development opportunities (online, classroom, conferences)
Comprehensive benefits package (complementary health and life insurance)
Success Metrics
Success will be measured in a variety of areas, including but not limited to
Consistently ensure the on-time delivery and quality (first-time-right) of the projects
Bring innovative cost effective solutions
Achieve customer satisfaction
This job requires an awareness of any potential compliance risks and a commitment to act with integrity, as the foundation for the Company’s success, reputation and sustainable growth.
Company:
Airbus India Private LimitedEmployment Type:
Permanent-------
Experience Level:
ProfessionalJob Family:
Cyber SecurityBy submitting your CV or application you are consenting to Airbus using and storing information about you for monitoring purposes relating to your application or future employment. This information will only be used by Airbus.
Airbus is committed to achieving workforce diversity and creating an inclusive working environment. We welcome all applications irrespective of social and cultural background, age, gender, disability, sexual orientation or religious belief.
Airbus is, and always has been, committed to equal opportunities for all. As such, we will never ask for any type of monetary exchange in the frame of a recruitment process. Any impersonation of Airbus to do so should be reported to emsom@airbus.com.
At Airbus, we support you to work, connect and collaborate more easily and flexibly. Wherever possible, we foster flexible working arrangements to stimulate innovative thinking.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Agile Application security APT Automation AWS CASP+ CISSP Cloud Compliance Computer Science Encryption Firewalls GCP GIAC Incident response JavaScript KPIs Linux MITRE ATT&CK Monitoring OSCP Python Red team Risk assessment SANS Scripting Scrum SIEM SOAR SOC Splunk Threat detection UNIX Vulnerabilities Windows
Perks/benefits: Career development Conferences Flex hours Health care Insurance Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.