Live opening · Posted 7 days ago

TECHNICAL LEAD - SOC 2

Happiest Minds · Bengaluru, Karnataka, India (On-site)
Linkedin No
You are 7 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 7 days ago
CompanyHappiest Minds
LocationBengaluru, Karnataka, India (On-site)
Work modeNo
SourceLinkedin
Listed7 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
2 min from Linkedin publishing this role to us finding it
9 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
70,974 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

File integrity Monitoring & Cyber Security Incident Management
As part of this profile, the resource will perform the following:
Platform Management and Administration
Administer and manage the NNT Change Tracker FIM, including deployment, configuration, troubleshooting, and ongoing platform optimization.
Ensure platform health, availability, and secure operation across all POS machines.
Onboarding and offboarding
Onboarding of POS machines based on the new store opening and PCI-scope countries
Configuring the FIM rules
Offboarding of agents based on the store closing request
Troubleshooting and Issue Resolution
Monitor, identify, and resolve platform-related issues, including:
Application and console functionality
Communication with POS machines
SIEM Integration
Engage with support processes to address any anomalies that impact tool effectiveness.
Health Monitoring and Availability
Continuously monitor the status and availability of all assets onboarded to the platform.
Address failures or downtime to ensure uninterrupted detection coverage.
SOC Integration and Alerting
Ensure effective integration between Canary and the Security Operations Center (SOC), including:
Event forwarding to SIEM
Alert correlation
Escalation of alerts within SOC processes
Validate alert quality and reduce false positives through periodic reviews.
Vendor Coordination
Act as the main point of contact with the NNT Change Track vendor for:
Technical support
Issue resolution
Product updates and enhancements
Track and manage support tickets and ensure timely closure.
Access Management and Governance
Manage user accounts and roles for the NNT change tracker management console.
Conduct quarterly access reviews to validate access rights and enforce the principle of least privilege.
Documentation and SOP Maintenance
Develop, maintain, and regularly update Standard Operating Procedures (SOPs) for:
Agent deployment
Incident response for alerts
Platform maintenance and upgrade
Integration workflows
Integration and Security Ecosystem Alignment
Integrate Canary with other security platforms, such as:
SIEM
Threat intelligence systems
Incident response and ticketing platforms
Ensure deception data enriches MAF?s overall security monitoring and detection framework.
Business Continuity and Disaster Recovery
Develop, maintain, and periodically test BC/DR plans for the NNT platform and related assets.
Validate platform recovery capabilities in the event of disruption or attack.
Incident Sources Covered
Monitor, integrate, and respond to incidents originating from, the following sources:
Akamai Web Application Firewall (WAF)
Extended Detection and Response (XDR) Managed Services (e.g., CrowdStrike)
Endpoint Detection and Response (EDR) solutions
Bug Bounty and Vulnerability Disclosure Platforms (e.g., Bugcrowd)
Security Operations Center (SOC) alerts (from SIEM/SOAR platforms)
Threat Intelligence Feeds (e.g., Anomali, vendor advisories)
Internal User and Business Reporting Channels
Application Performance Monitoring (APM) alerts (e.g., New Relic)
General Service Requirements
Demonstrate a thorough understanding of cybersecurity incident management and align with industry best practices.
Ensure immediate and appropriate response to incidents according to predefined severity levels and Incident Management Processes.
Investigate incidents thoroughly, document actions taken, and comply with reporting requirements.
Retain all records and logs related to security incidents and investigations.
Implement corrective and preventive measures based on the incident's root cause.
Support incident detection and alerting from Retail-specific APM tools (e.g., New Relic), ensuring coordination between development, application, and security teams.
Standardize incident handling processes through documented playbooks.
Coordinate incident resolution actions across IT, application, and infrastructure teams, ensuring closure within agreed SLAs.
Support internal investigations led by MAF (Majid Al Futtaim) teams as required.
Review and recommend enhancements to SOC use cases for better detection capabilities.
Support and manage related ticket types including LSM (Log Source Management), SCM (Security Configuration Management), and Threat Intelligence Tickets.
Detection & Intake
Continuously monitor and collect security events from all listed sources.
Validate and normalize alerts, eliminating false positives to focus on genuine incidents.
Initial Analysis & Triage
Confirm the authenticity of reported incidents.
Determine the nature, origin, and threat actor behaviour.
Categorize incidents based on their potential impact and urgency.
Severity Classification
Assign severity levels (e.g., P1, P2, P3) based on predefined business impact criteria, data sensitivity, and operational risk.
Ensure P1 incidents are treated as high-priority events requiring immediate containment and escalation.
Follow the agreed severity classification framework for consistency.
Incident Containment
Execute immediate containment actions such as isolating compromised systems, blocking malicious traffic, or disabling compromised accounts.
Recommend and coordinate appropriate mitigation steps with responsible technical teams.
Escalation & Coordination
Initiate a "War Room" (bridge call) for all P1 incidents to ensure rapid response coordination.
Engage relevant stakeholders, including BISO (Business Information Security Officer), system owners, and impacted business units.
Maintain continuous real-time status updates and detailed documentation during the incident lifecycle.
Remediation Support
Provide guidance on necessary remediation actions to relevant IT teams.
Ensure full eradication of Indicators of Compromise (IoCs).
Coordinate activities such as patching, system hardening, and control implementations where necessary.
Communication & Updates
Deliver timely incident status updates to stakeholders.
Document all incident actions, decisions, and timelines within the incident management and tracking platforms.
Post-Incident Analysis & RCA
Conduct Root Cause Analysis (RCA) for all P1 incidents and select significant P2 incidents.
Identify underlying security gaps and propose improvement recommendations.
Produce a formal RCA report with detailed findings, lessons learned, and corrective action plans.

Work arrangement
No

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App