Responsibilities
- Design and manage secure, segmented security platforms such as SIEM, EDR, and XDR that support large-scale, multi-client operations.
- Lead technical assessments of third-party tools, rigorously testing new technologies to establish standardized global security solutions.
- Create standardized system baselines and automated provisioning templates aligned with CIS and NIST guidelines to enable fast and secure client onboarding.
- Act as the highest-level technical authority for the SOC, directing responses to advanced persistent threats and critical security incidents.
- Perform in-depth root cause investigations following security events and convert findings into organization-wide preventive controls.
- Develop automation scripts using Python, PowerShell, and Terraform to streamline threat response, isolation, and patch deployment.
- Engineer custom API connections between vulnerability detection tools, remote monitoring systems, and service desks to enable automatic remediation workflows.
- Provide strategic guidance to major clients, interpreting technical risks into executive-level business continuity and improvement plans.
- Manage the collection and documentation of technical evidence required for compliance with HIPAA, SOC 2, and CMMC standards, ensuring continuous audit readiness.