- Location
- BLR, AMR TECH PARK 2A - 1F - Service, India
- Workplace
- Remote
- Type
- Full-time
- Experience
- 2+ years
- Closing date
- Today
- Source
- Workday
Description
Sagility combines industry-leading technology and transformation-driven BPM services with decades of healthcare domain expertise to help clients draw closer to their members. The company optimizes the entire member/patient experience through service offerings for clinical, case management, member engagement, provider solutions, payment integrity, claims cost containment, and analytics. Sagility has more than 25,000 employees across 5 countries.
Job title:
Job Description:
Job Title
Security Operations Center (SOC) Analyst
About the Department
Information Security - Security Operations Center (SOC). The SOC is the front line of Sagility’s cyber-defense, providing 24x7 monitoring, detection, triage, incident response and threat analysis across all operating geographies (India, Philippines, Jamaica, Colombia and the USA).
Job Role
A hands-on Security Operations resource responsible for monitoring, analyzing and responding to security events and incidents, spanning Tier 1 (monitoring & triage) and Tier 2 (investigation & response) activities. Key focus areas:
- Daily events log analysis and security alerts/alarm handling from the SIEM.
- Monitor and analyze IPS threat feeds, endpoints, network, cloud and email for indicators of compromise.
- Triage, investigate and drive incidents to closure with zero misses and 100% SLA adherence.
- Conduct forensic triage and support vulnerability assessment closure.
Shift
Rotational shifts, including night shifts, to support 24x7 SOC coverage
Location
India (Bangalore preferred) - supporting Sagility’s SOC operations globally
Responsibilities
Responsibilities grow in depth and autonomy from Tier 1. Common duties apply for the Tier 1 sections define clear demarcation.
- Protect the organization’s assets by upholding the principles of the Quality Information Security Management System (QISMS).
- Ensure confidentiality, integrity and availability of information, that is critical to Sagility’s business functions and client commitments.
- Report information-security incidents, losses, weaknesses and malfunctions to the right authority without any delay.
- Participate in training, orientation and awareness programs pertaining to QISMS and SOC processes.
Tier 1 (Level 1) - Monitoring & Triage Focus
- Perform daily events log analysis and monitor security alerts/alarms from the SIEM.
- Monitor closure of Critical Events and Security Alerts and notify concerned groups - targeting zero misses and 100% SLA.
- Perform daily and monthly review and analysis of IPS (e.g., Cisco Firepower) threat feeds and flag notable/reported threats and possible intrusions.
- Prepare and analyze daily monitoring reports for Sagility sites, servers and network devices (100% compliance).
- Create ad-hoc analysis of unusual events and user activities, or upon request by concerned groups or departments.
- Escalate validated incidents to Tier 2 with complete context per defined runbooks and SLAs.
Qualifications
- Graduate of a 4 to 5-year course - Computer Science, Information Technology, Engineering or any IT-related course.
- A strong internal drive for pursuing continuous learning and improvement.
Tier 1 Analyst
- 2 to 5 years of experience in a SOC, NOC, IT security or related monitoring function (freshers with relevant internships / certifications considered).
- Basic understanding of security monitoring, SIEM concepts, and incident-handling fundamentals.
- Certification (any one, preferred): CompTIA Security+, ISC2 Certified in Cybersecurity (CC), any SOC Analyst certificate, any Cisco security certificate, Microsoft SC-900.
Tools / Applications
- SIEM platforms, IPS/IDS (e.g., Cisco Firepower), EDR, vulnerability scanners, email-security and cloud-security tooling; MS Office, Visio and ticketing systems.
Location: