Hiring.Camp

T2 NOC Analyst

Cubic

·

Yesterday

Location
IND Hyderabad Aparna, India
Type
Full-time
Source
Workday

Description

Business Unit:

Cubic Transportation Systems

Company Details:

EXECUTIVE SUMMARY
Cubic Transportation Systems (CTS) is establishing a centralized, 24 hour by 7 day (24x7) global Network Operations Center (NOC) to monitor 35+ customer program implementations spanning regional field-service data centers and Microsoft Azure and Amazon Web Services (AWS) cloud tenants that support Payment Card Industry Data Security Standard (PCI DSS) v4.x scoped fare and payment processing. Tier 2 (T2) NOC Technicians sit between frontline Tier 1 (T1) monitoring and Tier 3 (T3) engineering, and perform two co-equal essential duties: validated-incident remediation using defined runbooks and playbooks (escalating to T3 only when no playbook exists or deeper technical guidance is required), and driving patching operations across each assigned program's environments.
Operations must comply with the International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) 27001:2022 standard, follow Information Technology Infrastructure Library (ITIL) 4 practices, support PCI DSS v4.x, and support National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0 outcomes. This document describes the detailed roles and responsibilities of the T2 NOC Technician role and the standards basis for that operating model.

Job Details:

Scope and Operating Context

The NOC monitors 35+ global program implementations, each a distinct Cubic customer, managed day-to-day by regional field service operations in customer-site data centers and/or in Azure or AWS cloud tenants. Monitored elements include network, systems, services, and internal processes critical to operations, as well as an array of Operational Technology (OT) devices including fare gates, ticket vending machines, point-of-sale (POS) devices, and mobile applications. The NOC also ensures processes for backup, log management, and operational security remain fully operational.

Patching operations are a significant and growing share of T2 workload. Each program averages 5 or more environments, and each environment averages approximately 150 Linux and Windows assets, located in a physical customer-site data center and/or an Azure cloud tenant. Two T2 NOC engineers are dedicated to each program to support this effort, and it consumes the majority of their time. DevOps automation intended to make patch orchestration more efficient is in progress but not yet mature; until it matures, a significant amount of hands-on T2 time is required.

Compliance basis: ISO/IEC 27001:2022, PCI DSS v4.x, ITIL 4, and NIST CSF 2.0.

Tier Model and Escalation Path

Tier 1 (T1) staff perform 24x7 monitoring; once they have identified a validated issue, they escalate to Tier 2 (T2) staff for remediation. Operations issues route to NOC T2 staff; security issues route to Security Operations Center (SOC) T2 staff. If the issue has a known remediation path with a defined playbook, T2 staff resolve it directly. If there is no defined playbook, or deeper technical guidance is needed, T2 staff engage Tier 3 (T3) engineers.

Tier 1 (T1) -

Function : 24x7 event triage, initial diagnosis, ticket creation, execution of approved runbooks, stakeholder communications.

Escalation Trigger: Escalates validated issues to Tier 2 (Ops to NOC, Security to SOC).

Tier 2 (T2) -

Function : Deeper troubleshooting, incident remediation, patching operations, correlation across regions and programs, coordination with regional field service operations and cloud teams.

Escalation Trigger: Escalates to Tier 3 when no defined playbook exists or deeper technical guidance is required.

Tier 3 (T3) -

Function : On-call product/platform engineering, complex database, storage, and network remediation, emergency design changes.

Engaged by Tier 2 on escalation; leads complex or novel remediation.

Escalation Trigger: NOC-to-SOC routing: operational anomalies that may be security-significant (spikes in authentication failures, unusual administrative actions, unexpected database audit patterns, web application firewall block surges, file integrity or tamper alerts) are escalated by the NOC to the SOC with enriched context, while the NOC continues operational containment under pre-approved playbooks.

Tier 2 NOC Technician: Roles and Responsibilities

Monitoring, Event Correlation, and Incident Remediation

• Perform deeper technical triage on incidents escalated from Tier 1, correlating events across regions, sites, and cloud tenants.

• Execute approved remediation runbooks and playbooks to restore service, consistent with ITIL 4 Incident Management practice.

• Engage Tier 3 engineers when no defined playbook exists or when the issue requires deeper technical guidance.

• Lead or support major incident coordination for assigned programs, including stakeholder communications and resolution validation.

Patching Operations (Co-Equal Essential Duty)

• Drive patch execution across the 5 or more environments of each assigned program, covering an average of 150 Linux and Windows assets per environment.

• Coordinate patch windows and maintenance schedules with regional field service operations and customer stakeholders.

• Apply patches and remediations cleared by engineering and tested prior to release, maintaining process and records compliance.

• Support ongoing DevOps automation of patch orchestration as tooling matures, and flag environments not yet covered by automation.

Incident Management and Major Incident Support

• Validate alerts, identify impacted services and sites, and set incident priority based on impact and urgency.

• Apply containment-first mitigations within the first 15 to 30 minutes of a declared incident (reroute traffic, failover, isolate a site segment, stop a bad deployment).

• Support the incident commander role for major incidents affecting an assigned program.

• Produce post-incident documentation: timeline, root cause hypothesis, mitigation, residual risk, and follow-up actions.

Change and Configuration Management

• Ensure every production change has a ticket, risk assessment, test evidence, rollback plan, and required approvals before implementation.

• Monitor configuration baselines for network devices, operating system hardening, and cloud security posture; raise incidents for drift affecting availability or security.

• Execute pre-approved emergency change procedures when required, with after-the-fact Change Advisory Board review and evidence capture.

Log Management (Operational Review)

• Verify log source coverage for network devices, operating systems, identity and access management, database audit logs, and application logs.

• Validate Network Time Protocol (NTP) health across sites and cloud tenants so that logs remain forensically useful.

• Perform operational review of logs for availability and performance signals; escalate security-relevant alerts to the SOC.

Backup and Recovery Verification

• Perform daily verification of backup job success, failure, duration anomalies, and missed schedules.

• Participate in periodic restore validation, including file-level and full service-level restores.

Business Continuity and Disaster Recovery Support

• Maintain and help exercise failover and failback runbooks for assigned programs' cloud regions and customer-site data centers.

• Track disaster recovery readiness gaps as risk items and support remediation change requests.

Security Monitoring at the Operational Layer (NOC-to-SOC Interface)

• Monitor for operational anomalies that may be security-significant and escalate to the SOC with enriched context.

• Support containment under pre-approved playbooks (network isolation, account lock, traffic throttling) while the SOC leads investigation when security-incident criteria are met.

Documentation and Reporting

• Maintain and review runbooks, standard operating procedures (SOPs), service maps, and escalation paths for assigned programs.

• Produce daily operations summaries and contribute to weekly service level agreement (SLA) and key performance indicator (KPI) dashboards.

• Participate in postmortems and problem-record analysis to reduce recurring incidents.

Compliance and Standards Cross-Reference

The table below cross-references core Tier 2 NOC activity areas to their governing standards basis.

1)

NOC Task Area : 24x7 monitoring, event correlation, alert tuning

ITIL 4 Practice : Monitoring and Event Management; Incident Management

ISO/IEC 27001:2022 : A.8.16 Monitoring Activities; A.8.15 Logging

PCI DSS v4.x : Req 10 Log/Monitor; Req 11 Test Security

NIST CSF 2.0 : Detect; Respond

2)

NOC Task Area : Incident triage, escalation, major incident coordination

ITIL 4 Practice : Incident Management

ISO/IEC 27001:2022 : A.8.15/A.8.16 evidence

PCI DSS v4.x : Req 12 security program; 12.10 Incident Response

NIST CSF 2.0 : Respond

3)

NOC Task Area : Patching, config drift detection, emergency change evidence

ITIL 4 Practice : Change Enablement; Service Configuration

ISO/IEC 27001:2022 : A.8.32 Change Management

PCI DSS v4.x : Req 2 secure configurations; Req 6 secure systems/software

NIST CSF 2.0 : Protect; Govern

4)

NOC Task Area : Log onboarding, integrity, retention checks

ITIL 4 Practice : Monitoring and Event Management; Information Security Management

ISO/IEC 27001:2022 : A.8.15 Logging; A.8.16 Monitoring Activities

PCI DSS v4.x : Req 10 logging and monitoring

NIST CSF 2.0 : Detect; Respond

5)

NOC Task Area : Backup job verification, restore tests

ITIL 4 Practice : Service Continuity Management; Availability Management

ISO/IEC 27001:2022 : A.8.15 Logging; A.8.16 Monitoring Activities

PCI DSS v4.x : Req 3/4 data protection posture supported

NIST CSF 2.0 : Protect; Recover

6)

NOC Task Area : Operational security anomaly monitoring; escalation to SOC

ITIL 4 Practice : Information Security Management; Monitoring and Event Management

ISO/IEC 27001:2022 : A.8.16 monitoring anomalies; A.8.15 logging

PCI DSS v4.x : Req 10 monitoring; Req 12.10 24x7 readiness

NIST CSF 2.0 : Protect; Recover

Worker Type:

Employee

We are committed to creating an inclusive workplace and welcome applications from people of all backgrounds. We do not discriminate based on any protected characteristic under applicable law.

Skills

AWSAzureLinuxCybersecuritySOCDevOpsComplianceChange ManagementITIL