Consultant - CyberSecurity
LTM · Hartford, CT · 3 wk ago
On-siteConsultingFull-time
About the Role
This is a high-priority P1 role in a Security Operations Centre (SOC) focusing on real-time threat detection, incident response, and proactive defense. As a P1 SOC Monitoring Analyst, you will be responsible for real-time monitoring, triage, and escalation of security incidents using advanced cybersecurity tools. You will act as the first line of defense against cyber threats, ensuring rapid detection and response across endpoints, networks, cloud environments, and email systems.
Responsibilities
- Real-Time Monitoring & Triage: Monitor security alerts and logs from CrowdStrike EDR, IDP, NextGenXOR, Logscale, Microsoft Defender, SIEM, and ORCA. Analyze and triage alerts based on severity, impact, and relevance to business operations.
- Threat Detection & Response: Investigate suspicious activities using Threat Intel Advisories, DHS CRISPEISAC feeds, and internal threat intelligence. Escalate confirmed incidents to L2/L3 teams with detailed analysis and recommendations.
- Email & Endpoint Security: Monitor and respond to email-based threats using Proofpoint. Ensure endpoint protection and behavioral analysis through CrowdStrike and Microsoft Defender.
- Cloud & Network Security: Monitor cloud workloads and configurations using ORCA. Analyze traffic and application behavior via F5 WAF and Zscaler for anomalies and policy violations.
- Azure Entra ID Management: Manage Microsoft Entra ID (Azure AD), including user/group management, MFA, Conditional Access policies, PIM, and Identity Protection. Integrate Entra ID with third-party and on-premises applications for SSO and federation. Enforce least privilege through RBAC. Deploy and manage security tools like Microsoft Defender for Cloud, Sentinel, and Azure Policy. Conduct security assessments and audits.
- Documentation & Reporting: Maintain incident logs, timelines, and evidence. Generate daily/weekly reports on SOC activities, threat trends, and tool performance.
Requirements
- 2+ years of experience in SOC or cybersecurity operations.
- Hands-on experience with: CrowdStrike EDR/IDP, Logscale, SIEM (Splunk, QRadar, Logscale), Microsoft Defender, Proofpoint, F5 WAF, Zscaler, ORCA, CRISPEISAC feeds, and Microsoft Azure Entra ID.
- Strong understanding of MITRE ATT&CK framework, incident response lifecycle, and threat hunting.
- Ability to work under pressure and manage multiple high-priority tasks.
- Excellent communication and documentation skills.
Qualifications
- Preferred Certifications: CompTIA Security+, Certified SOC Analyst (CSA), CrowdStrike Certified Falcon Administrator, Microsoft SC-200 Security Operations Analyst Associate.
Benefits
- Comprehensive Medical Plan (Medical, Dental, Vision)
- Short-Term and Long-Term Disability Coverage
- 401(k) Plan with Company Match
- Life Insurance
- Vacation Time, Sick Leave, Paid Holidays
- Paid Paternity and Maternity Leave
Actual compensation within the range will be dependent upon the individual's skills, experience, performance, and internal equity. Benefits/perks may vary depending on the nature of employment with LTIMindtree.