Summary:
The Sr Security Engineer/Lead Cyber Incident Response Team (CIRT) Member will play a critical role in managing and coordinating responses to cybersecurity incidents. This position is responsible for overseeing the detection, analysis, and mitigation of security threats, ensuring timely and effective incident response, and leading the organization's efforts to protect its assets from cyberattacks. The Sr Security Engineer acts as a point of contact during security events, liaises with other IT and security departments, and ensures proper procedures are followed to minimize damage and prevent future incidents.
Principal duties and responsibilities:
Incident Detection and Analysis:
Monitor security systems and event logs to detect potential security breaches. Perform detailed analysis of security incidents to determine their scope, root cause, and impact. Lead investigations into complex cybersecurity incidents, such as data breaches or advanced persistent threats (APTs). Incident Response and Mitigation:
Coordinate the immediate response to security incidents,
including containment, eradication, and recovery activities. Lead incident response teams to quickly mitigate active threats and prevent further damage. Ensure the deployment of countermeasures and corrective actions to safeguard the organization. Communication and Reporting:
Act as the main point of contact during active incidents, communicating status updates to executives, IT teams, and relevant stakeholders. Prepare detailed incident reports, outlining actions taken and lessons learned. Provide briefings to senior management on incident findings, risks, and mitigations. Team Leadership and Coordination:
Lead a team of cybersecurity analysts, providing guidance, mentorship, and oversight on incident response practices. Collaborate with other IT and security departments to ensure a unified approach to incident handling and remediation. Organize regular incident response drills and tabletop exercises t