Information Security Operations Specialist
Indexed description
Job Description
Job Summary
Information Security Lead with 8-12 years of extensive experience in Security Operations Center (SOC), Incident Response (IR), proactive Threat Hunting, Threat Intelligence & Vulnerability Management and handling complex security escalations. The candidate will act as a senior escalation point for high-severity security incidents, conduct advanced investigations, develop threat hunting hypotheses, and provide actionable intelligence to improve the organization’s overall security posture.
The role requires hands-on expertise across SIEM, EDR/XDR, network security monitoring, malware analysis, threat intelligence platforms, and cloud security monitoring.
Roles & Responsibilities:
- Coordinate and lead incident response activities for cybersecurity incidents.
- Ensure timely escalation, containment, eradication, and recovery from security incidents.
- Experience in handling P1 incidents, driving investigation till closure.
- Lead complex investigations, handle critical escalations from L1/L2 teams, and perform root-cause analysis
- Provide analysis and trending of security log data from security devices.
- Hands-on experience with SIEM platforms such as Microsoft Sentinel.
- Experience working with SOAR platforms and security automation technologies.
- Hands-on experience with EDR/XDR solutions such as Microsoft Defender XDR, CrowdStrike Falcon.
- Experience with vulnerability management tools such as Qualys, Tenable, or Rapid7 is preferred.
- Good to have knowledge and experience in Advance SOC environment, SOC automation, AI usage in SOC.
- Perform threat hunting and proactive security investigations.
SOC Operations
- Lead day-to-day Security Operations Center (SOC) operations.
- Ensure effective security monitoring, incident detection, investigation, response, and resolution in accordance with defined SLAs.
- Act as the primary operational escalation point for critical and high-severity security incidents.
- Coordinate major incident response activities with internal technical teams, and external stakeholders.
- Monitor operational KPIs, service quality, and SLA compliance, driving continuous service improvements.
- Review and approve incident reports, root cause analysis (RCA), and post-incident review documentation.
- Ensure accurate incident documentation and timely communication throughout the incident lifecycle.
- 24x7 on call support to team members.
- Creating runbooks/playbooks and SOPs.
Security Monitoring & Threat Detection
- Oversee continuous monitoring using SIEM, SOAR, EDR/XDR, and other security technologies.
- Review, validate, and optimize SIEM correlation rules, detection use cases, alert tuning, and dashboards.
- Lead threat hunting initiatives and support proactive identification of advanced threats.
- Work closely with Threat Intelligence teams to operationalize Indicators of Compromise (IOCs) and emerging threat intelligence.
- Ensure timely investigation and escalation of suspicious activities and security events.
- Team Leadership
- Lead, mentor, and manage a team of internal L3 Security Analysts & collaborate with external vendor L1/L2 security analysts, fostering a culture of collaboration, accountability, and continuous learning.
- Provide technical guidance and support during complex investigations and major security incidents.
- Conduct performance reviews, one-on-one mentoring, and technical coaching sessions.
- Identify training needs and support professional development through knowledge-sharing sessions, simulations, and tabletop exercises.
- Review analyst investigations and incident handling to ensure quality, consistency, and adherence to operational procedures.
Threat Intelligence
- Proficient in intelligence analysis, analytical models and threat intelligence frameworks such as the cyber kill chain and the diamond model.
- Skilled in OSINT gathering and OSINT investigations.
- Familiar with threat intelligence tools such as threat intelligence platforms.
- Experienced with navigation and collecting information from dark web sources.
- Proficient at extracting tactics, techniques and procedures from reporting and mapping them to the MITRE ATT&CK framework.
- Proven experience analyzing and responding to advanced persistent threats, malware campaigns, and cyber-attacks
- Monitor global threat landscape, including adversary tactics, techniques, and procedures (TTPs), to anticipate and mitigate risks
- Correlate intelligence with internal telemetry to identify vulnerabilities, indicators of compromise (IOCs), and potential attack vectors
- Drive continuous improvement of threat intelligence processes, tooling, and frameworks Collaborate cross-functionally with IT, digital, and business teams to embed threat intelligence into security strategy and operations
- Provide mentorship and technical guidance to junior analysts, acting as a domain expert
- Evaluate external intelligence sources, vendors, and technologies to strengthen intelligence capabilities
- Support executive decision-making by translating complex threats into business risk impacts
Vulnerability Management
- Proficiency with vulnerability scanning tools (e.g., Nessus, Qualys, Rapid7) and familiarity with security frameworks (e.g., NIST, ISO 27001).
- Ability to analyze vulnerability data, assess risks, and prioritize responses based on potential impact.
- Good understanding of Windows, UNIX and Linux operating systems functions and security.
- Perform thorough risk assessments on identified vulnerabilities, considering both the technical aspects and the business context.
- Collaborate with IT and OT teams to prioritize and facilitate the timely patching of vulnerabilities.
- Prepare detailed reports on vulnerability findings, including risk assessments, recommended actions, and patch management status.
- Develop and maintain Vulnerability Management policies, procedures, and related documentation to ensure consistent and effective practices.
- Stay abreast of the latest cybersecurity threats and vulnerabilities, incorporating this intelligence into Vulnerability Management processes.
- Communicate effectively with various stakeholders, including IT and OT teams, management, and external partners, to ensure a comprehensive understanding of vulnerabilities, impacts, and mitigation strategies.
- Provide expertise and support during cybersecurity incidents related to vulnerabilities.
- Assist in compliance efforts and audits, ensuring that Vulnerability Management practices meet industry standards and regulatory requirements.
- Regularly review and recommend improvements to the Vulnerability Management program to enhance security posture.
Preferred Certifications
- GCIH - GIAC Certified Incident Handler
- GCIA - GIAC Certified Intrusion Analyst
- CEH - Certified Ethical Hacker
- Microsoft Certified: Security Operations Analyst (SC-200)
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search