Responsibilities
- Monitor endpoints and assess security alerts, assisting in incident response from detection to resolution while aiding in root cause investigations
- Examine suspected malware infections and anomalous system behavior
- Reduce alert overload by refining detection rules, improving prioritization, and optimizing response workflows
- Serve as a technical authority in at least one key security area, such as network surveillance, Microsoft security platforms, or automated threat mitigation
- Conduct proactive threat hunting across the organization’s IT environment to detect vulnerabilities, new threats, and ongoing attacks
- Help develop and maintain security protocols, operational guides, and procedural documentation
- Assist in escalating security incidents and engage in critical incident response activities when necessary
- Mentor junior team members, share expertise across departments, and promote organization-wide security awareness
- Stay current on evolving cyber threats and propose enhancements to detection strategies and monitoring capabilities
- Participate in a rotating on-call schedule as part of the Security Operations team, currently involving one week of on-call duty every five weeks
Other
Participate in a rotating on-call schedule as part of the Security Operations team, currently one week in every five