Responsibilities
- Lead the complete incident management process, from detection to containment, eradication, and recovery.
- Analyze emerging cyber threats and incorporate external intelligence sources into detection systems.
- Conduct in-depth forensic analysis on endpoints and network traffic to uncover root causes and attacker persistence methods.
- Develop and improve automated security orchestration playbooks to enhance response efficiency and reliability.
- Proactively search for hidden threats using hypothesis-based investigation techniques across systems and networks.
- Serve as the primary contact for escalated security events and guide junior team members in advanced analysis methods.
- Prepare comprehensive incident documentation and communicate technical findings clearly to both technical teams and leadership.