KPMG Ukraine

Security Operations Center - Assistant Manager

KPMG Ukraine  •  Noida, IN (Onsite)  •  4 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Roles & responsibilities

We are seeking a highly skilled and proactive SOC L2 Analyst to join our Cyber Security Operations team. The candidate will be responsible for advanced monitoring, investigation, analysis, and response to cybersecurity incidents using Splunk SIEM, CrowdStrike Falcon, and Microsoft Defender for Endpoint (MDE). The role requires strong analytical capabilities, incident response expertise, threat hunting experience, and the ability to mentor L1 analysts while contributing to the continuous improvement of security operations.


Note : Candidate must be willing to do 24x7 rotational shift (Mandatory requirement for this role)

Educational Qualifications:

Bachelor's degree in Computer Science, Information Security, Cybersecurity, Information Technology, Engineering, or a related field.
Master's degree in Cybersecurity, Information Security, or related discipline is preferred.
Minimum 6 years of experience in Security Operations Center (SOC), Incident Response, or Cyber Defense operations.
Experience working in a 24x7 SOC environment supporting enterprise-scale security monitoring and incident management.

Experience Requirements:

6-8 years of hands-on experience in SOC Operations, Incident Response, Threat Hunting, or Cyber Defense, with demonstrated expertise in Splunk SIEM, CrowdStrike Falcon, and Microsoft Defender for Endpoint (MDE) in enterprise environments.

The Ideal Candidate Will

Investigate and respond to security alerts and incidents escalated by L1 analysts.
Perform advanced threat analysis, triage, containment, eradication, and recovery activities.
Be able to perform live response via Defender or Crowdstrike to perform cleanup of the detected malware etc.
Conduct threat hunting activities using telemetry from Splunk, CrowdStrike, and Microsoft Defender for Endpoint.
Correlate events from multiple security platforms to identify sophisticated attack patterns and anomalies.
Lead incident investigations and provide detailed root cause analysis (RCA).
Develop and improve use cases, correlation rules, dashboards, and detection content within Splunk.
Analyze endpoint security incidents including malware, ransomware, phishing, credential compromise, insider threats, and advanced persistent threats (APTs).
Collaborate with IT, Network, Cloud, Endpoint, and Infrastructure teams during incident response activities.
Contribute to incident response playbooks, standard operating procedures (SOPs), and knowledge repositories.
Perform threat intelligence analysis and incorporate indicators of compromise (IOCs) into monitoring processes.
Provide mentorship and guidance to L1 analysts and assist in skill development initiatives.
Participate in post-incident reviews and recommend security control improvements.
Support compliance, audit, and reporting requirements related to security operations.

Roles & responsibilities

We are seeking a highly skilled and proactive SOC L2 Analyst to join our Cyber Security Operations team. The candidate will be responsible for advanced monitoring, investigation, analysis, and response to cybersecurity incidents using Splunk SIEM, CrowdStrike Falcon, and Microsoft Defender for Endpoint (MDE). The role requires strong analytical capabilities, incident response expertise, threat hunting experience, and the ability to mentor L1 analysts while contributing to the continuous improvement of security operations.


Note : Candidate must be willing to do 24x7 rotational shift (Mandatory requirement for this role)

Educational Qualifications:

Bachelor's degree in Computer Science, Information Security, Cybersecurity, Information Technology, Engineering, or a related field.
Master's degree in Cybersecurity, Information Security, or related discipline is preferred.
Minimum 6 years of experience in Security Operations Center (SOC), Incident Response, or Cyber Defense operations.
Experience working in a 24x7 SOC environment supporting enterprise-scale security monitoring and incident management.

Experience Requirements:

6-8 years of hands-on experience in SOC Operations, Incident Response, Threat Hunting, or Cyber Defense, with demonstrated expertise in Splunk SIEM, CrowdStrike Falcon, and Microsoft Defender for Endpoint (MDE) in enterprise environments.

The Ideal Candidate Will

Investigate and respond to security alerts and incidents escalated by L1 analysts.
Perform advanced threat analysis, triage, containment, eradication, and recovery activities.
Be able to perform live response via Defender or Crowdstrike to perform cleanup of the detected malware etc.
Conduct threat hunting activities using telemetry from Splunk, CrowdStrike, and Microsoft Defender for Endpoint.
Correlate events from multiple security platforms to identify sophisticated attack patterns and anomalies.
Lead incident investigations and provide detailed root cause analysis (RCA).
Develop and improve use cases, correlation rules, dashboards, and detection content within Splunk.
Analyze endpoint security incidents including malware, ransomware, phishing, credential compromise, insider threats, and advanced persistent threats (APTs).
Collaborate with IT, Network, Cloud, Endpoint, and Infrastructure teams during incident response activities.
Contribute to incident response playbooks, standard operating procedures (SOPs), and knowledge repositories.
Perform threat intelligence analysis and incorporate indicators of compromise (IOCs) into monitoring processes.
Provide mentorship and guidance to L1 analysts and assist in skill development initiatives.
Participate in post-incident reviews and recommend security control improvements.
Support compliance, audit, and reporting requirements related to security operations.

Roles & responsibilities

We are seeking a highly skilled and proactive SOC L2 Analyst to join our Cyber Security Operations team. The candidate will be responsible for advanced monitoring, investigation, analysis, and response to cybersecurity incidents using Splunk SIEM, CrowdStrike Falcon, and Microsoft Defender for Endpoint (MDE). The role requires strong analytical capabilities, incident response expertise, threat hunting experience, and the ability to mentor L1 analysts while contributing to the continuous improvement of security operations.


Note : Candidate must be willing to do 24x7 rotational shift (Mandatory requirement for this role)

Educational Qualifications:

Bachelor's degree in Computer Science, Information Security, Cybersecurity, Information Technology, Engineering, or a related field.
Master's degree in Cybersecurity, Information Security, or related discipline is preferred.
Minimum 6 years of experience in Security Operations Center (SOC), Incident Response, or Cyber Defense operations.
Experience working in a 24x7 SOC environment supporting enterprise-scale security monitoring and incident management.

Experience Requirements:

6-8 years of hands-on experience in SOC Operations, Incident Response, Threat Hunting, or Cyber Defense, with demonstrated expertise in Splunk SIEM, CrowdStrike Falcon, and Microsoft Defender for Endpoint (MDE) in enterprise environments.

The Ideal Candidate Will

Investigate and respond to security alerts and incidents escalated by L1 analysts.
Perform advanced threat analysis, triage, containment, eradication, and recovery activities.
Be able to perform live response via Defender or Crowdstrike to perform cleanup of the detected malware etc.
Conduct threat hunting activities using telemetry from Splunk, CrowdStrike, and Microsoft Defender for Endpoint.
Correlate events from multiple security platforms to identify sophisticated attack patterns and anomalies.
Lead incident investigations and provide detailed root cause analysis (RCA).
Develop and improve use cases, correlation rules, dashboards, and detection content within Splunk.
Analyze endpoint security incidents including malware, ransomware, phishing, credential compromise, insider threats, and advanced persistent threats (APTs).
Collaborate with IT, Network, Cloud, Endpoint, and Infrastructure teams during incident response activities.
Contribute to incident response playbooks, standard operating procedures (SOPs), and knowledge repositories.
Perform threat intelligence analysis and incorporate indicators of compromise (IOCs) into monitoring processes.
Provide mentorship and guidance to L1 analysts and assist in skill development initiatives.
Participate in post-incident reviews and recommend security control improvements.
Support compliance, audit, and reporting requirements related to security operations.
KPMG Ukraine

About KPMG Ukraine

KPMG – це міжнародна мережа фірм, що надають аудиторські, податкові та консультаційні послуги. В офісах KPMG у 143 країнах світу працюють понад 273,000 співробітників (FY23). Кожна фірма KPMG є незалежною юридичною особою і представляє себе як таку.

KPMG працює в Україні з 1992 року. KPMG в Україні надає аудиторські, податкові, бухгалтерські та консультаційні послуги для місцевих і міжнародних компаній. Нашою метою завжди було використання глобального інтелектуального потенціалу фірми в поєднанні з практичним досвідом наших українських професіоналів, щоб допомогти провідним компаніям досягти своїх цілей.

Офіси компанії знаходяться у Києві та Львові.

______________

KPMG is a global network of professional services firms providing audit, tax and advisory services. We operate in 143 countries and territories, and in FY23, collectively employed more than 273,000 people working in member firms around the world.

KPMG in Ukraine provides audit, tax, accounting and advisory services to local and international businesses. KPMG has been working in Ukraine since 1992, and our goal has always been to use the firm's global intellectual potential, combined with the practical experience of our Ukrainian professionals, to help leading companies to achieve their goals.

In Ukraine KPMG has its offices in Kyiv and Lviv.

Industry
Consulting & Advisory
Company Size
201-500 employees
Headquarters
Kyiv, UA
Year Founded
1992
Website
kpmg.com
Social Media