hostinservices
Job Title: SOC Analyst Intern Location: Pune Department: Security Operations Center (SOC)
We are looking for a motivated and enthusiastic SOC Analyst Intern to join our Cybersecurity team. This internship offers an excellent opportunity to gain hands-on experience in Security Operations, Cloud Security, Incident Response, SIEM, and Web Application Security. Role Description : Opportunity to work across key security domains (such as Cloud, zero trust, Identity & Access, Data) Deployment of Security services like WAF, BOT protection, and Anti-DDoS (L3/L7) working in close conjunction with security architecture, vendors, and internal stakeholders. Contribute to global strategy work and process of onboarding of applications and APIs behind security controls. Monitor and manage the health of WAF/BOT/DDoS security controls. Maintain good security posture Develop, maintain, test, and troubleshoot policies and rule sets globally. Monitors systems activities and fine-tune system parameters and configuration to optimize performance and ensure the security of systems. Respond to security events and contribute to incident response plans. Review and respond to WAF/BOT/DDoS alerts, onboard new apps to these security controls, optimize policies, lead/conduct upgrades, integrate with monitoring/alerting tools, and troubleshoot issues. Support operational tasks for WAF/BOT/DDoS to assist, solve, and advise on issues associated with WAF/BOT/DDoS services within prescribed SLA. Support on-call rotation. Open vendor support cases as required and track to closure. Security enthusiast with strong hands-on experience and broad knowledge across the security domain. The ideal candidate should have knowledge of various security tools and services and will be a part of a managed SOC team. Preferred Knowledge of security domains related to monitoring & response, perimeter security, cloud security, application security, endpoint security, network security, data security, risk & compliance, and hands-on experience on at least one SIEM. Roles and responsibilities: Responsible for 24x7 alerts monitoring and tracking Incidents on SIEM and EDR, reporting & escalation, regular SIEM administration, enforcement of network & cloud security policies, research on new security technologies for integrating them in SOC, along with the security monitoring & log analysis of multi-vendor security solutions Configuring monitoring policies, alerts, procedures, and standards relating to SOC practices for the security domains viz. network security, perimeter security, cloud security, data security, zero trust, etc. Identify security measures to improve incident response. Respond to security incidents. Should be able to coordinate incident response across teams. Should be able to perform security assessments and audits. Should be able to provide technical solutions to security vulnerabilities. Research new attack vectors. Providing frontline support for applications and their infrastructure Respond, troubleshoot, and provide resolution to the production alerts. Analyse trends to proactively prevent incidents. Assist in security vulnerability and remediation. Participation in an on-call rotation and operating effectively in a global 24x7 environment Ability to learn new technologies quickly with some support and guidance Troubleshoot incidents, identify root cause, fix and document problems, and implement preventive measures Participate in innovation and developing monitoring systems smarter Automated response to security incidents (malware infections, unauthorized access, malicious emails, DDoS attacks, etc, together with evaluating the type, nature and severity of security events (security assurance/security compliance) through the use of a range of security event analysis tools. Assess security technologies and data in place to propose relevant Security use cases (mostly from a security incidents monitoring perspective) Technical Understanding : Domain knowledge of web applications, and associated protocols (HTTP/S, SSL, DNS, TCP/IP) Familiarity with common web application security concepts such as the OWASP Top 10. Various Monitoring Services and tools like CloudWatch, Grafana, New Relic AWS Security Services. WAF (WAAP): Working knowledge of WAF, API, Bot Control, and Exposure to technology platforms - AWS WAF, F5, Imperva, technology is required. Understanding of DDoS attacks on Layers 3,4, and 7 Proficiency with popular tools in the industry of AppSec and their usage: Burp Suite, Postman, Wireshark