Responsibilities
- Evaluate and act on security alerts from internal systems, user reports, and external service providers.
- Assist in controlling and resolving cybersecurity incidents, following established procedures and service-level agreements.
- Investigate security alerts by analyzing logs and contextual data through the SIEM platform and related technologies, with full documentation.
- Oversee and enhance the firm's threat intelligence sources to ensure they are accurate, relevant, and actionable.
- Develop and lead long-term threat intelligence planning, especially in response to emerging risks from artificial intelligence.
- Create and operate a proactive threat hunting program to detect suspicious activity before it causes harm.
- Advance digital forensics capabilities by selecting and managing appropriate tools and processes.
- Perform forensic examinations of company devices and data, working with security, legal, and HR teams as necessary.
- Collect and preserve digital evidence using legally sound methods, maintaining a documented chain of custody for potential legal proceedings.
- Lead internal coordination for offensive and collaborative security testing exercises, defining goals and scope.
- Oversee third-party providers conducting security tests and ensure identified issues are addressed and resolved.
- Monitor and manage ongoing performance of external security vendors to meet contractual and operational expectations.
- Serve as the primary internal contact to align vendor activities with organizational security goals.
- Support risk assessments of third parties handling sensitive data, in collaboration with procurement and risk management teams.
Work Arrangement
On-site — New York