Join Metron Security as a SOC Lead and take charge of our dynamic Security Operations Center! Lead a talented team, oversee threat detection, incident response, and ensure top-notch security for our clients. If you're passionate about cybersecurity and leadership, this is your chance to make a real impact!
Role And Responsibilities
Implementation of the SOC using open-source security tools including EDRs, SIEMs, etc.
Make sure all the tools used within Metron are monitored by SOC. Wherever needed, integrate the tools with SOC.
Monitor all the activities from the Metron laptops and the Cloud tools used within Metron.
Identify the gaps in the Metron infrastructure and processes.
Suggest and enforce security best practices.
Conduct security audits.
Stay up-to-date on the latest security threats.
Conduct internal security awareness training sessions for all employees.
Knowledge of SIEM, SOAR, ePO, XDR and end points
Prepare reports that document security breaches and the extent of the damage caused by the breaches.
Ensuring endpoints and networks are free of breaches by proactively analysing the logs from critical devices.
Develop security standards and best practices for Metron.
Research the latest information technology (IT) security trends and report breaches alerted by vendors.
Recommend security enhancements to management or senior IT staff.
Establishes system controls by developing a framework for controls and levels of access based on NIST standards; recommending improvements.
Support compliance requirements and related efforts.
Ensures authorised access by investigating improper access; revoking access; reporting violations; monitoring information requests by new programming; recommending improvements.
Develop security reports and publish periodically.
Review the tickets/escalations from L1, L2 Analysts.
SOC Team Shift Roster Management & Keep Security Operation Centre running 24x7.
Operation & process flow creation & building Operation process stability.
Train soc Team on Security devices, policies, security Analysis, threat hunting, Implementation of new capabilities.
Implementing the Automation scope to reduce load from team & process normalisation.
Documentation, building playbooks & review.
Performance matrix for SOC.
Task & role assignment for team on the security tools based on capabilities.
Continuously finding Gap & implementing the fix for the SOC operations.
Experienced in managing multiple global programs and projects.
Proficient in using SCRUM, JIRA and Confluence tools.
Skills and Experience:
SCRUM, Jira, Confluence
Knowledge of SPLUNK, Cortex XDR, SOAR Automation
Basic AWS Security, CNAP
Knowledge of Proofpoint, McAfee or Threat Intel, equivalent,
Reporting & Review Public/Private Key Certificate Infrastructure
Windows, Linux, MAC
Encryption methodologies
Experience in cloud architecture and security aspects
Experience In Leading SOX,ISO, Audit And Compliance Requirements