Introduction
A career in IBM Consulting is rooted by long-term relationships and close collaboration with clients across the globe. You'll work with visionaries across multiple industries to improve the hybrid cloud and AI journey for the most innovative and valuable companies in the world. Your ability to accelerate impact and make meaningful change for your clients is enabled by our strategic partner ecosystem and our robust technology platforms across the IBM portfolio
Your role and responsibilities
MSS L1(Triage) analyst are first responders during security incidents (24/7/365).
Monitoring the organization's network to identify the potential threats.
By reviewing the SIEM alerts to categories the severity and issue types Shift Leads will instruct the triage team to perform the required actions.
Team on triage Steps (Identify, Analyze and Action)
Triage analyst will analyze the payload and validate the IP reputations, ports, files, hashes, file path, usernames and other host detail.
Quick search on rule index and add possible artifacts to the alert based on their extended research in alerts in Glass console.
Checking historical records in the knowledge base to find if any similar alerts were reported in the past.
Providing the initial recommendations to the stakeholder's team and escalate to XFTM L2 Analyst for detailed investigation to take further action.
Creating tuning request & suggesting for the modification of SIEM rules if team come across any false positive or excessive noise in client environments
Required education
Bachelor's Degree
Required technical and professional expertise
* Cloud-Based Solution Exposure: Exposure to providing 24/7 technical support for cloud-based solutions, including experience with various applications, DevOps, middleware, security, and infrastructure components. * Infrastructure Configuration Experience: Experience working with infrastructure and configuration as code using Ansible and Terraform, including administering Dev, Test, and Production environments hosted on Windows, Linux, and Unix servers. * Database Administration Knowledge: Exposure to installing and configuring databases such as MYSQL, MSSQL, and PostgreSQL. * Cloud Vendor Familiarity: Experience working with load balancing and CDN options provided by multiple cloud vendors, including Azure Load Balancer and Application Gateway. * IT Service Management Knowledge: Familiarity with ITIL processes and Integrated Service Level Management, including experience with service management reporting and providing regular updates to clients.
Preferred technical and professional experience
* Familiarity with Kubernetes: Exposure to managing Kubernetes nodes, including experience with container orchestration and deployment. * Knowledge of Microservices: Understanding of microservices architecture and experience with service discovery, API gateways, and service mesh. * Experience with ICP Management: Exposure to managing ICP components, including experience with infrastructure provisioning and deployment.