About this role
<p><strong>Responsible Domains as below:<br><br></strong></p> <p><strong>1. Monitoring & Detection</strong></p> <ul> <li>Monitor security alerts from various sources, including SIEM (Security Information and Event Management), EDR (Endpoint Detection and Response), firewalls, and IDS/IPS systems.</li> <li>Triage incoming alerts to distinguish between benign events and genuine security incidents.</li> <li>Maintain and tune use cases within the SIEM to reduce false positives and improve detection capabilities.<br><br></li> </ul> <p><strong>2. Incident Response & Management</strong></p> <ul> <li>Lead the technical response to security incidents, including malware outbreaks, ransomware, phishing campaigns, data leaks, and unauthorized access.</li> <li>Perform digital forensics, including disk and memory analysis, to determine the root cause and scope of an incident.</li> <li>Contain, eradicate, and recover from security incidents, ensuring business continuity.</li> <li>Document every step of the incident lifecycle, creating detailed after-action reports and timelines.<br><br></li> </ul> <p><strong>3. Threat Hunting & Analysis</strong></p> <ul> <li>Proactively search for signs of advanced persistent threats (APTs) or malicious activity that may have evaded existing security controls.</li> <li>Analyze threat intelligence feeds to understand the current threat landscape and anticipate potential attacks against the organization.<br><br></li> </ul> <p><strong>4. Communication & Reporting</strong></p> <ul> <li>Communicate technical findings to non-technical stakeholders, including management and legal teams, during active incidents.</li> <li>Prepare post-incident reports that include root cause analysis, lessons learned, and remediation recommendations.</li> <li>Escalate critical incidents according to the incident response plan.<br><br></li> </ul> <p><strong>5. Process Improvement</strong></p> <ul> <li>Recommend and implement improvements to security tools, policies, and playbooks based on lessons learned from incidents.</li> <li>Collaborate with the IT and Development teams to ensure vulnerabilities are patched and configurations are hardened.</li> </ul> <p><strong><br><br>Qualifications & Requirements<br><br></strong></p> <ol> <li><strong>Education:</strong> Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or a related field (or equivalent practical experience).</li> <li><strong>Experience:</strong> 3+ years of experience in information security, with a focus on incident response, security operations, or threat analysis.</li> <li><strong>Tools:</strong> Proficiency with SIEM platforms (e.g.,ELK), EDR tools (e.g., CrowdStrike, SentinelOne, Defender ATP), and NDR tools (e.g., Darktrace).</li> <li><strong>Forensics:</strong> Experience with digital forensics tools and techniques (e.g., EnCase, FTK, Volatility, Autopsy) is a plus.</li> <li><strong>Operating Systems:</strong> Deep understanding of Windows and Linux operating systems, including logging mechanisms, file systems, and common persistence mechanisms.</li> <li><strong>Cloud:</strong> Familiarity with cloud security and incident response in AWS, AliCloud, or GCP environments.</li> <li><strong>Scripting:</strong> Proficiency in scripting languages such as Python, PowerShell, or Bash for automation and log analysis.</li> <li><strong>Frameworks:</strong> Solid understanding of the Cyber Kill Chain, MITRE ATT&CK framework, and NIST incident response lifecycle.</li> <li><strong>Analytical Thinking:</strong> Exceptional problem-solving skills and the ability to think like an attacker.</li> <li><strong>Communication:</strong> Excellent written and verbal communication skills; ability to explain complex technical issues to a non-technical audience.</li> <li><strong>Stress Management:</strong> Ability to remain calm and methodical under pressure during active security breaches. Must be willing to work during non-office hours and ad-hoc request during incident support.</li> <li><strong>Certifications (Preferred but not mandatory)</strong></li> </ol> <ul> <li>GIAC Certified Incident Handler (GCIH)</li> <li>Certified Information Systems Security Professional (CISSP)</li> <li>CompTIA Security+</li> <li>Certified Ethical Hacker (CEH)</li> </ul>