Key Responsibilities. Incident Response and Management: Lead the response to complex security incidents, including advanced persistent threats (APTs), malware outbreaks, and data breaches. Conduct thorough forensic analysis to determine the root cause of security incidents and provide recommendations for remediation. Collaborate with other IT teams to contain, mitigate, and recover from security incidents.
Threat Hunting: Proactively identify potential threats by analyzing logs, network traffic, and other security-related data. Develop and implement threat-hunting techniques to detect advanced threats that may evade automated detection systems. Continuously improve threat detection capabilities by integrating new intelligence sources and refining existing detection rules. Security Monitoring and Analysis: Monitor security alerts generated by SIEM (Security Information and Event Management) systems, IDS/IPS, firewalls, and other security tools.
Analyze security events to identify potential security incidents and escalate them as needed. Develop and fine-tune security monitoring rules, use cases, and playbooks to improve detection accuracy. Show more Show less