A career in IBM Consulting is rooted by long-term relationships and close collaboration with clients across the globe. You'll work with visionaries across multiple industries to improve the hybrid cloud and AI journey for the most innovative and valuable companies in the world. Your ability to accelerate impact and make meaningful change for your clients is enabled by our strategic partner ecosystem and our robust technology platforms across the IBM portfolio
MSS L1(Triage) analyst are first responders during security incidents (24/7/365).
Monitoring the organization's network to identify the potential threats.
By reviewing the SIEM alerts to categories the severity and issue types Shift Leads will instruct the triage team to perform the required actions.
Team on triage Steps (Identify, Analyze and Action)
Triage analyst will analyze the payload and validate the IP reputations, ports, files, hashes, file path, usernames and other host detail.
Quick search on rule index and add possible artifacts to the alert based on their extended research in alerts in Glass console.
Checking historical records in the knowledge base to find if any similar alerts were reported in the past.
Providing the initial recommendations to the stakeholder's team and escalate to XFTM L2 Analyst for detailed investigation to take further action.
Creating tuning request & suggesting for the modification of SIEM rules if team come across any false positive or excessive noise in client environments
Interest in Cybersecurity - preferably with education background in security