Responsibilities
- Analyze and respond to security incidents forwarded from the initial detection team
- Conduct detailed technical investigations to determine the underlying causes of security events
- Implement actions to contain threats and remediate affected systems, networks, and security infrastructure
- Apply measures to reduce impact and prevent recurrence of security incidents
- Oversee incidents from escalation through to final resolution
- Enhance detection capabilities by refining and expanding SIEM use cases
- Design and maintain automated incident response procedures using SOAR platforms
- Record solutions, processes, and process enhancements in the internal knowledge repository
- Support ongoing refinement of security operations workflows and protocols
Work Arrangement
On-site