Sr Soc Threat Analyst - Tier3

3 Months ago • All levels • Cyber Security

Job Summary

Job Description

The Sr. SOC Threat Analyst - Tier 3 at Zelis will be responsible for creating, modifying, and tuning SIEM rules; integrating various log sources (Windows, Linux, Palo Alto firewall, AWS, etc.); providing correlation rule tuning, incident classification, and prioritization recommendations; optimizing SIEM system capabilities; working with network, device, and policy teams; identifying new threats; monitoring enterprise log correlation; selecting, designing, implementing, and managing security measures; collecting, analyzing, and interpreting vulnerability data; conducting vulnerability/exploit research; handling customer escalations; investigating security vulnerabilities; troubleshooting security issues; developing custom scripts; analyzing CVE information; monitoring and analyzing Cortex XDR alerts; troubleshooting and configuring prevention policies; utilizing vulnerability features in spotlight; performing daily PAM tasks (reconciliation, health checks, compliance reports); managing privileged session management and policies; creating and managing platforms, policies, and safes for privileged IDs; managing privileged user accounts; developing documentation; analyzing and investigating security events; performing forensic analysis; monitoring security threats; providing guidance and training to junior analysts; collaborating with security engineers; identifying opportunities for improving security processes; and staying updated on cybersecurity trends.
Must have:
  • SIEM expertise (rule creation, tuning, integration)
  • Vulnerability management & analysis
  • XDR monitoring & incident response
  • PAM administration & policy management
  • Threat hunting & investigation skills
  • Forensic analysis capabilities
  • Security event response & coordination

Job Details

About the job

Technical Skills

SIEM – Skills

Create, modify, and tune the SIEM rules to adjust the specifications of alerts and incidents.

Knowledge Integrating various log sources like Windows, Linux, Pala alto firewall , AWS, Etc.

To provide continual correlation rule tuning, incident classification and prioritization recommendations.

Report query adjustments, and various other SIEM configuration activities.

Ability to fully optimize the SIEM system capabilities as well as the audit and logging features of the event log sources.

Work closely with the other teams related to Network, Device, Policy, connectivity issues etc.

Identify new opportunities/threats in the network to improve the security of the network

Monitor and administer enterprise log correlation (SIEM)

Select, design, implement and manage security measures to reduce the risk of loss

VM – Skills

Collecting, analyzing, interpreting, evaluating, and integrating vulnerability data from multiple sources to update existing product

Vulnerability/exploit research and creating signatures for the same

Handle Customer escalations, to identify False-Positive & False-Negative

Actively investigate the latest in security vulnerabilities, advisories, incidents, and provide insights (sources like, Microsoft, Oracle, etc)

Troubleshooting security vulnerability issues/ gaps that arise

Vulnerability data discovery and validation (Data efficacy & Accuracy)

Develop, test and modify custom scripts for vulnerability content

Manually/Automate analyzing new CVE information published

XDR - Skills

Monitor and analyzing Threat hunting, Deep investing on Cortex XDR Alerts, Detection, Incidents.

Troubleshoot and Configure Prevention Policies, Custom IOA Rule Groups, Detections Management, Exclusions, IOC Management, Firewall Policies, Firewall Rule Groups, USB Device Policies, Response Policies, Response Scripts & Files, Containment Policy, Sensor Update Policies.

Should be able to check and utilize all Vulnerability feature in spotlight.

PAM- Skills

Perform daily tasks that include reconciliation of servers, daily health check of the PAM servers, run daily compliance reports, etc.

Manage Privileged Session Management and associated policies.

Create and manage Platforms, Policies and Safes for Privileged ID’s.

Responsible for Privileged User account administration for various platforms including Windows, UNIX, LDAP, Databases.

Manage Service Accounts, Non-Production Accounts, Test Accounts within the vaults.

Develop and maintain documentation for security systems and procedures.

Reporting and metrics

Management Skills

  • Analyse, investigate, lead and coordinate responses to complex, advanced security events and alerts, perform forensic analysis to understand extent of compromise by using respective tools.
  • Monitor, analyse security threats, vulnerabilities and trends by utilize threat intelligence to enhance detection and response capabilities.
  • Provide guidance, conduct trainings and support to level 1 and 2 SOC analysts
  • Collaborate, Assist with security engineers to deploy, develop, implement and manage security tools and architecture.
  • Work closely with IT and security teams to coordinate efforts
  • Identify opportunities for improving security processes and technology
  • Stay upto date on cybersecurity trends and threats.
  • documenting security incidents, responses and related information in accordance with procedures.

Zelis is modernizing the healthcare financial experience by providing a connected platform that bridges the gaps and aligns interests across payers, providers, and healthcare consumers. This platform serves more than 750 payers, including the top 5 national health plans, BCBS insurers, regional health plans, TPAs and self-insured employers, and millions of healthcare providers and consumers. Zelis sees across the system to identify, optimize, and solve problems holistically with technology built by healthcare experts – driving real, measurable results for clients.

Commitment to Diversity, Equity, Inclusion, and Belonging

At Zelis, we champion diversity, equity, inclusion, and belonging in all aspects of our operations. We embrace the power of diversity and create an environment where people can bring their authentic and best selves to work. We know that a sense of belonging is key not only to your success at Zelis, but also to your ability to bring your best each day.

Equal Employment Opportunity

Zelis is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

We encourage members of traditionally underrepresented communities to apply, even if you do not believe you 100% fit the qualifications of the position, including women, LGBTQIA people, people of color, and people with disabilities.

Accessibility Support

We are dedicated to ensuring our application process is accessible to all candidates. If you are a qualified individual with a disability or a disabled veteran and require a reasonable accommodation with any part of the application and/or interview process, please email TalentAcquisition@zelis.com.

SCAM ALERT: There is an active nationwide employment scam which is now using Zelis to garner personal information or financial scams. This site is secure, and any applications made here are with our legitimate partner. If you’re contacted by a Zelis Recruiter, please ensure whomever is contacting you truly represents Zelis Healthcare. We will never asked for the exchange of any money or credit card details during the recruitment process. Please be aware of any suspicious email activity from people who could be pretending to be recruiters or senior professionals at Zelis.

Similar Jobs

PwC - SRC_Cyber Strategy

PwC

Bengaluru, Karnataka, India (On-Site)
3 Months ago
Microsoft - Digital Technology Specialists - Security - French Speaker

Microsoft

Dublin, County Dublin, Ireland (Hybrid)
1 Month ago
Trend Micro - Automotive Research Engineer - Threat Intelligence & Content Creation (VicOne)

Trend Micro

Taipei City, Taiwan (On-Site)
4 Months ago
PwC - Security Operations Center and Incident Response Manager

PwC

Makati, Metro Manila, Philippines (On-Site)
4 Months ago
Axinous - Senior Software Development Manager - C, Linux, Distributed Systems

Axinous

Bengaluru, Karnataka, India (Hybrid)
1 Month ago
Varonis  - Cloud Security Researcher

Varonis

Herzliya, Tel Aviv District, Israel (On-Site)
4 Months ago
Playtika - Application Security Researcher

Playtika

Israel (On-Site)
3 Months ago
Applike - IT Security Manager (f/m/d)

Applike

Hamburg, Hamburg, Germany (Hybrid)
1 Month ago
PwC - IT Audit Associate

PwC

Makati, Metro Manila, Philippines (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Trend Micro - Automotive Research Engineer - Threat Intelligence & Content Creation (VicOne)

Trend Micro

Taipei City, Taiwan (On-Site)
4 Months ago
Postman - Senior Security Engineer, Detection & Response

Postman

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Anavation - Cyber Threat Analyst

Anavation

Reston, Virginia, United States (On-Site)
2 Months ago
Rush Street Interactive - Threat Intelligence Analyst

Rush Street Interactive

Serbia (On-Site)
1 Month ago
ByteDance - Full-Stack Software Engineer - 2025 Start

ByteDance

Singapore (On-Site)
3 Months ago
Reversing Labs - Product Marketing Manager, Software Supply Chain Security

Reversing Labs

United States (Remote)
2 Months ago
Reversing Labs - Channel Account Manager (US Central & West)

Reversing Labs

United States (Remote)
2 Months ago
ByteDance - Full-Stack Software Engineer - Security Operation Center

ByteDance

San Jose, California, United States (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Hyderabad, Telangana, India

Framestore - Compositor

Framestore

Mumbai, Maharashtra, India (On-Site)
3 Months ago
PwC - AES SAP ABAP Senior Manager

PwC

Hyderabad, Telangana, India (On-Site)
4 Months ago
Assystems - Senior Urban Planner

Assystems

Gurugram, Haryana, India (On-Site)
3 Months ago
Wipro - Release Manager

Wipro

Bengaluru, Karnataka, India (On-Site)
3 Months ago
PwC - IN_Senior Associate_SAP ISU_Utility transformation_Advisory_Jaipur

PwC

Jaipur, Rajasthan, India (On-Site)
2 Months ago
Luxoft - Murex QA Tester

Luxoft

New Delhi, Delhi, India (Remote)
3 Months ago
JOBSTARS HR SOLUTIONS PRIVATE LIMITED - React Native

JOBSTARS HR SOLUTIONS PRIVATE LIMITED

Thrissur, Kerala, India (Hybrid)
5 Months ago
SparkCognition - Recruiter

SparkCognition

Bengaluru, Karnataka, India (On-Site)
5 Months ago
Keywords Studios (Player Support) - Software Engineer- Lead

Keywords Studios (Player Support)

Pune, Maharashtra, India (On-Site)
2 Months ago
OneScreenai - Senior Manager- OOH Media Planner

OneScreenai

India (Remote)
4 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

PwC - CD&E-ServiceNow developer -Associate 2-Hyderabad

PwC

Hyderabad, Telangana, India (On-Site)
3 Months ago
ION - Cyber Product Owner, Italy

ION

Italy (Hybrid)
4 Months ago
PwC - Cybersecurity Governance Experienced Consultant (m/f/d)

PwC

Luxembourg (On-Site)
4 Months ago
PwC - Digital Asset Manager

PwC

Amman, Amman Governorate, Jordan (On-Site)
4 Months ago
Halma plc - Cyber Security Engineer

Halma plc

Bengaluru, Karnataka, India (On-Site)
3 Months ago
PwC - IN-Manager_AWS Engineer_Advisory Corporate_Advisory_Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
4 Months ago
PwC - Associate - Mumbai Shivaji Park - Technology Consulting

PwC

Mumbai, Maharashtra, India (On-Site)
4 Months ago
Ubisoft - Physical Security Analyst

Ubisoft

Montreal, Quebec, Canada (On-Site)
1 Month ago
Cotiviti - Senior Security Engineer

Cotiviti

(On-Site)
4 Months ago
Microsoft - Software Engineer - Cloud and Enterprise Security

Microsoft

(On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded