Security Architect
Accenture
Accenture
Join our cybersecurity team as a Security Managed Services Senior Analyst, contributing to building secure and resilient businesses. This full-time role focuses on advanced security operations within a dynamic threat landscape.
We are seeking an experienced professional to investigate complex security alerts and incidents. You will be instrumental in validating escalated events, enriching them with crucial context, and collaborating with advanced teams for swift containment and remediation. Your expertise will also drive improvements in detection capabilities and support security automation initiatives.
This position demands a deep understanding of detection, investigation, containment, and remediation strategies. Essential to the role is the ability to collaborate effectively across various security, IT, and compliance teams to ensure robust protection for our clients.
- Investigate escalated security alerts to pinpoint scope, impact, and root cause. - Conduct in-depth analysis of endpoints and networks using SentinelOne. - Validate threats and perform endpoint analysis utilizing SentinelOne capabilities. - Correlate diverse log sources within Splunk to trace attacker activities. - Execute and verify SOAR playbooks for containment, such as host isolation or user account disablement. - Enhance events with vital asset, identity, and threat intelligence context. - Document investigation processes, evidence gathered, and final conclusions. - Assist L3 analysts during major incidents with log or memory triage. - Propose enhancements to alert logic or SOAR workflows to minimize false positives. - Engage in threat research aligned with alert patterns and business needs.
- A minimum of 3 years of dedicated experience in Security Information and Event Management (SIEM). - At least 2 years of experience specifically in a Level 2 Incident Response (IR) role within a Security Operations Center (SOC). - Demonstrated experience in 24x7 operational environments, shift-based work, or critical infrastructure response. - Proficiency in investigating escalated alerts using SIEM or EDR tools. - Experience in incident response and containment activities. - Ability to identify and implement automation opportunities within security workflows. - Familiarity with EDR deep dive techniques, including Real Time Response (RTR) and custom rules. - Skill in writing SPL queries, creating dashboards, and fine-tuning SIEM configurations. - Experience with threat hunting methodologies based on TTPs. - Solid understanding of malware, lateral movement, privilege escalation, and data exfiltration patterns. - Experience with threat intelligence integration and IOC lookups. - Competence in forensic analysis, including live host forensics and log correlation. - Proficiency with SentinelOne forensic and incident response features. - Capability to define, update, and optimize IR playbooks and workflows. - Experience with cloud incident handling (AWS, Azure). - Advanced dashboarding skills for business-focused metrics in Splunk.
Accenture
IT Consulting