T

MDR

Tata Consultancy Services · Delhi, Delhi, India

2–8 yrs experiencefull_timePosted 1w ago

Job description

**Key Responsibilities** **1. Monitoring & Offense Management** - Monitor security events and alerts through **QRadar dashboards, consoles, and offense queues** . - Conduct initial and detailed investigation of offenses, determine true/false positives, and escalate as required. - Perform log enrichment, event correlation analysis, and offense deep‑dive using QRadar tools. **2. Investigation & Incident Response** - Investigate suspicious activities (credential misuse, lateral movement, DNS anomalies, exfiltration, malware behavior). - Perform root‑cause analysis (RCA) for confirmed incidents. - Document incident timelines, artifacts, and technical findings in SOC case management tools. - Coordinate containment, eradication, and recovery steps with relevant teams. **3. AQL Search & Log Analysis** - Use **AQL (Ariel Query Language)** for advanced searches, pivoting, and correlation. - Analyze logs from Windows/Linux servers, network devices, EDR, cloud services, and applications. - Build actionable dashboards and custom queries to support threat‑hunting and investigations. **4. Use Case Management & Rule Tuning** - Review and tune **QRadar correlation rules, building blocks, reference sets, and threat models** . - Optimize detection rules to reduce false positives and improve alert fidelity. - Work with Threat Intelligence team to integrate IOCs, threat feeds, and enrichment sources. **5. Threat Hunting** - Conduct proactive hunts using QRadar events, anomalies, traffic patterns, and baselines. - Look for MITRE ATT&CK TTPs such as privilege escalation, persistence, lateral movement, and command‑and‑control communication. - Document hunt hypotheses, results, and recommended improvements. **6. QRadar Administration Support (as needed)** - Validate log source onboarding and troubleshoot ingestion issues. - Ensure log sources are normalized, parsed correctly, and categorized appropriately. - Participate in QRadar patching, upgrades, backup/restore tests, and HA validation (if required). **7. Reporting & Compliance** - Generate daily, weekly, and monthly security reports. - Provide data for compliance audits (ISO 27001, PCI‑DSS, RBI, GDPR, internal governance). Maintain all SOC documentation, SOPs, and detection playbooks.