Posted by
Recruiter
Last Active: NA as recruiter has posted this job through third party tool.
Posted in
IT & Systems
Job Code
1724399

Role: Head - Cyber Defense & Incident Response (M4)
Role Contour: Responsible for detection, triage, analysis, response and recovery from suspicious events and security incidents to maintain appropriate intelligence posture for VIL.
Accountability:
- Overseeing monitoring and co-relation of log events across IT infrastructure including security devices, network devices, applications, operating systems etc.
- Designing standard response procedures for security incidents, ensuring post-review of priority 1 and 2 incidents, following defined escalation path when needed, as defined in the escalation policy, etc.
- Performing blue team/red team exercises.
- Accountable to keep in pace with external threat intelligence and sharing leads with the architecture team for developing strategy and procuring security solutions to address the gap.
- Ensuring response to and recovery from security incidents, performing problem management, root cause analysis, developing after action reports for high-profile, high-impact incidents, sharing timely communication with relevant stakeholders and follow-up through closure of gaps and inconsistencies.
- Performing forensic analysis and supporting investigations (includes interfaces with law enforcement).
- Conducting hackathons/ bug bounty programmes to identify potential gaps in information security architecture; working closely with Anticipatory Security Architecture team for closure of those gaps.
- Leading and managing threat intel activities to ensure appropriate intelligence posture for future incidents.
- Creation & maintenance of relevant SOPs, protocols, policies and other internal documents; ensuring these are reviewed and updated on a timely basis and appropriate information is shared with relevant stakeholders in a timely manner.
- Compliance to all applicable regulatory and law enforcements/requirements, managing all the information.
- Managing the interaction with DOT/NCIIPC/CERT-in etc for intel advisory and Incident response related activities.
Experience & Qualifications:
- 20+ years exposure working in IT & Security, with minimum of 8 to 10 years in IT Security Management.
- Strong in Governance, Partner Engagement, team handling.
- Bachelors degree in Engineering, Cyber Security or related field.
- Certifications: CISSP/CCSP/CISA/CISM.
Dimensions:
- % adherence to SLA for resolving incidents based on incident categorization 99%.
- Number of cyber drills participated in and the ability to identify all test cases Twice in Year.
Technical Competencies:
- Understanding of Network and System administration.
- Building logic and algorithms.
- Understating of SIEM & other security tools like AV, DLP, EDR, Proxy etc.
- Understanding security systems & appliance like NIPS, DODOS, Firewall.
Didn’t find the job appropriate? Report this Job
Posted by
Recruiter
Last Active: NA as recruiter has posted this job through third party tool.
Posted in
IT & Systems
Job Code
1724399