- Location
- IND Hyderabad Aparna, India
- Type
- Full-time
- Source
- Workday
Description
Business Unit:
Cubic Transportation SystemsCompany Details:
EXECUTIVE SUMMARYCubic Transportation Systems (CTS) is establishing a centralized, 24 hour by 7 day (24x7) global Network Operations Center (NOC) to monitor 35+ customer program implementations spanning regional field-service data centers and Microsoft Azure and Amazon Web Services (AWS) cloud tenants that support Payment Card Industry Data Security Standard (PCI DSS) v4.x scoped fare and payment processing. Tier 2 (T2) NOC Technicians sit between frontline Tier 1 (T1) monitoring and Tier 3 (T3) engineering, and perform two co-equal essential duties: validated-incident remediation using defined runbooks and playbooks (escalating to T3 only when no playbook exists or deeper technical guidance is required), and driving patching operations across each assigned program's environments.
Operations must comply with the International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) 27001:2022 standard, follow Information Technology Infrastructure Library (ITIL) 4 practices, support PCI DSS v4.x, and support National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0 outcomes. This document describes the detailed roles and responsibilities of the T2 NOC Technician role and the standards basis for that operating model.
Job Details:
Scope and Operating Context
The NOC monitors 35+ global program implementations, each a distinct Cubic customer, managed day-to-day by regional field service operations in customer-site data centers and/or in Azure or AWS cloud tenants. Monitored elements include network, systems, services, and internal processes critical to operations, as well as an array of Operational Technology (OT) devices including fare gates, ticket vending machines, point-of-sale (POS) devices, and mobile applications. The NOC also ensures processes for backup, log management, and operational security remain fully operational.
Patching operations are a significant and growing share of T2 workload. Each program averages 5 or more environments, and each environment averages approximately 150 Linux and Windows assets, located in a physical customer-site data center and/or an Azure cloud tenant. Two T2 NOC engineers are dedicated to each program to support this effort, and it consumes the majority of their time. DevOps automation intended to make patch orchestration more efficient is in progress but not yet mature; until it matures, a significant amount of hands-on T2 time is required.
Compliance basis: ISO/IEC 27001:2022, PCI DSS v4.x, ITIL 4, and NIST CSF 2.0.
Tier Model and Escalation Path
Tier 1 (T1) staff perform 24x7 monitoring; once they have identified a validated issue, they escalate to Tier 2 (T2) staff for remediation. Operations issues route to NOC T2 staff; security issues route to Security Operations Center (SOC) T2 staff. If the issue has a known remediation path with a defined playbook, T2 staff resolve it directly. If there is no defined playbook, or deeper technical guidance is needed, T2 staff engage Tier 3 (T3) engineers.
Tier 1 (T1) -
Function : 24x7 event triage, initial diagnosis, ticket creation, execution of approved runbooks, stakeholder communications.
Escalation Trigger: Escalates validated issues to Tier 2 (Ops to NOC, Security to SOC).
Tier 2 (T2) -
Function : Deeper troubleshooting, incident remediation, patching operations, correlation across regions and programs, coordination with regional field service operations and cloud teams.
Escalation Trigger: Escalates to Tier 3 when no defined playbook exists or deeper technical guidance is required.
Tier 3 (T3) -
Function : On-call product/platform engineering, complex database, storage, and network remediation, emergency design changes.
Engaged by Tier 2 on escalation; leads complex or novel remediation.
Escalation Trigger: NOC-to-SOC routing: operational anomalies that may be security-significant (spikes in authentication failures, unusual administrative actions, unexpected database audit patterns, web application firewall block surges, file integrity or tamper alerts) are escalated by the NOC to the SOC with enriched context, while the NOC continues operational containment under pre-approved playbooks.
Tier 2 NOC Technician: Roles and Responsibilities
Monitoring, Event Correlation, and Incident Remediation
• Perform deeper technical triage on incidents escalated from Tier 1, correlating events across regions, sites, and cloud tenants.
• Execute approved remediation runbooks and playbooks to restore service, consistent with ITIL 4 Incident Management practice.
• Engage Tier 3 engineers when no defined playbook exists or when the issue requires deeper technical guidance.
• Lead or support major incident coordination for assigned programs, including stakeholder communications and resolution validation.
Patching Operations (Co-Equal Essential Duty)
• Drive patch execution across the 5 or more environments of each assigned program, covering an average of 150 Linux and Windows assets per environment.
• Coordinate patch windows and maintenance schedules with regional field service operations and customer stakeholders.
• Apply patches and remediations cleared by engineering and tested prior to release, maintaining process and records compliance.
• Support ongoing DevOps automation of patch orchestration as tooling matures, and flag environments not yet covered by automation.
Incident Management and Major Incident Support
• Validate alerts, identify impacted services and sites, and set incident priority based on impact and urgency.
• Apply containment-first mitigations within the first 15 to 30 minutes of a declared incident (reroute traffic, failover, isolate a site segment, stop a bad deployment).
• Support the incident commander role for major incidents affecting an assigned program.
• Produce post-incident documentation: timeline, root cause hypothesis, mitigation, residual risk, and follow-up actions.
Change and Configuration Management
• Ensure every production change has a ticket, risk assessment, test evidence, rollback plan, and required approvals before implementation.
• Monitor configuration baselines for network devices, operating system hardening, and cloud security posture; raise incidents for drift affecting availability or security.
• Execute pre-approved emergency change procedures when required, with after-the-fact Change Advisory Board review and evidence capture.
Log Management (Operational Review)
• Verify log source coverage for network devices, operating systems, identity and access management, database audit logs, and application logs.
• Validate Network Time Protocol (NTP) health across sites and cloud tenants so that logs remain forensically useful.
• Perform operational review of logs for availability and performance signals; escalate security-relevant alerts to the SOC.
Backup and Recovery Verification
• Perform daily verification of backup job success, failure, duration anomalies, and missed schedules.
• Participate in periodic restore validation, including file-level and full service-level restores.
Business Continuity and Disaster Recovery Support
• Maintain and help exercise failover and failback runbooks for assigned programs' cloud regions and customer-site data centers.
• Track disaster recovery readiness gaps as risk items and support remediation change requests.
Security Monitoring at the Operational Layer (NOC-to-SOC Interface)
• Monitor for operational anomalies that may be security-significant and escalate to the SOC with enriched context.
• Support containment under pre-approved playbooks (network isolation, account lock, traffic throttling) while the SOC leads investigation when security-incident criteria are met.
Documentation and Reporting
• Maintain and review runbooks, standard operating procedures (SOPs), service maps, and escalation paths for assigned programs.
• Produce daily operations summaries and contribute to weekly service level agreement (SLA) and key performance indicator (KPI) dashboards.
• Participate in postmortems and problem-record analysis to reduce recurring incidents.
Compliance and Standards Cross-Reference
The table below cross-references core Tier 2 NOC activity areas to their governing standards basis.
1)
NOC Task Area : 24x7 monitoring, event correlation, alert tuning
ITIL 4 Practice : Monitoring and Event Management; Incident Management
ISO/IEC 27001:2022 : A.8.16 Monitoring Activities; A.8.15 Logging
PCI DSS v4.x : Req 10 Log/Monitor; Req 11 Test Security
NIST CSF 2.0 : Detect; Respond
2)
NOC Task Area : Incident triage, escalation, major incident coordination
ITIL 4 Practice : Incident Management
ISO/IEC 27001:2022 : A.8.15/A.8.16 evidence
PCI DSS v4.x : Req 12 security program; 12.10 Incident Response
NIST CSF 2.0 : Respond
3)
NOC Task Area : Patching, config drift detection, emergency change evidence
ITIL 4 Practice : Change Enablement; Service Configuration
ISO/IEC 27001:2022 : A.8.32 Change Management
PCI DSS v4.x : Req 2 secure configurations; Req 6 secure systems/software
NIST CSF 2.0 : Protect; Govern
4)
NOC Task Area : Log onboarding, integrity, retention checks
ITIL 4 Practice : Monitoring and Event Management; Information Security Management
ISO/IEC 27001:2022 : A.8.15 Logging; A.8.16 Monitoring Activities
PCI DSS v4.x : Req 10 logging and monitoring
NIST CSF 2.0 : Detect; Respond
5)
NOC Task Area : Backup job verification, restore tests
ITIL 4 Practice : Service Continuity Management; Availability Management
ISO/IEC 27001:2022 : A.8.15 Logging; A.8.16 Monitoring Activities
PCI DSS v4.x : Req 3/4 data protection posture supported
NIST CSF 2.0 : Protect; Recover
6)
NOC Task Area : Operational security anomaly monitoring; escalation to SOC
ITIL 4 Practice : Information Security Management; Monitoring and Event Management
ISO/IEC 27001:2022 : A.8.16 monitoring anomalies; A.8.15 logging
PCI DSS v4.x : Req 10 monitoring; Req 12.10 24x7 readiness
NIST CSF 2.0 : Protect; Recover
Worker Type:
Employee
We are committed to creating an inclusive workplace and welcome applications from people of all backgrounds. We do not discriminate based on any protected characteristic under applicable law.