Soc Supervisor
E-Cop
• Support and guide Security Analyst in analyzing and handling log events, customized procedures, liaise with engineers and consultants during adaptive phase of projects. • 24 x7 for all SOC service reference point (ESM application, log collector, various in-house application and Web). New Security Analyst orientation. Tracking of and deliverables to client & SOC production statistic.• Liaise with MSS engineers/consultant during ISSS device deployment and on site troubleshooting in order to reduce device down time. • 2nd level escalation for daily operation issues including incident analysis, troubleshooting and process changes. Review and quality control all ISSS internal processes and clients’ request.• Supervised and support more than 50 ISSS clients locally and world wide. Review alert fine tuning created by the security analyst. Reduce false positive and potential of false negativeTechnical Expertise:• A few years of experience in log analysis from various types of security devices from multiple vendors.• Knowledge, skills, and ability to configure and monitor intrusion detection systems read, interpret, and analyze network traffic as well as correlate it with related log files.• Intimately familiar with the nuts and bolts of Snort IDS rule fine tuning, testing, output analysis, tagging and etc• Widely experience in using various security tools (such as tcpdump, nmap, hping, scapy, wireshark) in analysing intrusion in order to identify abnormal stimulus response.