Job Summary
Handling critical incidents/escalations, reviewing incidents and tracking towards closure also Initiate (P1,P2,P3) to coordinate & collaborate within the technical tracks to look for a remediation solution for a security incident.
Participate in setting up the policies, practices, and procedures for incident command center/ situation management.
Understand the security incident and take necessary actions to coordinate with respective stakeholders to remediate the incident in the defined SLA. Good to have knowledge of Security Tools (SEIM, Crowd Strike, and endpoint protection).
Develop and maintain incident response playbooks and runbooks. Train teams on incident handling procedures and communication protocols.
Coordinate forensic analysis, intrusion detection, and threat mitigation.
Work with various teams including business, technical, administrative to identify the Root Cause of the Problem / incident and work with them to apply the remediation to resolve the incident immediately.
Take necessary actions to coordinate through collaboration tools (Emails, calls, chat etc.) and work with various business and technical teams to resolve the incident in the defined timelines.
Host/Lead incident calls with active participation, ask prompting questions, maintain incident meeting notes, publish actions, resolutions etc.
Publish Incident reports during and after the Situation Management. Work closely with various platforms / tools (Windows, Network / Security etc.) and business owners to resolve the incident and capture action items.
Block Malicious IPs, Domains, SHA values, Reset Passwords and Kill MFA sessions. Un- contain/ Contain the machines through different tools.
Continuously evolve IT Service Management (ITSM) practices for an effective Incident Response.
Manage Cyber Crisis Response and work with various supporting functions (Legal, HR, Finance, Procurement, Physical security, Privacy, R&C, Insurance Company, Treat Intel Provider etc.) to take necessary reactive / corrective actions as per defined Incident Response Plan (IRP).
Key Responsibilities
2. To Coordinate With Outsourced Vendors And Ensure Smooth Delivery Of Work
3. To Lead And Manage The It Team
4. To Participate In Audits And Work Towards Compliance To Ipr
5. To Participate In Rfps| Rfis And New It Infra Creations
6. To Provide Budget Inputs To The Function Head And Manage Costs Within The Assigned Area
7. To Review The Operations And Resolve Or Escalate The User Escalations To Other Domain Vertical Teams