As a Senior Technical Incident Responder, your primary duties will include:
- Acting as a technical leader for alerts and incidents within the SOC.
- Communicating technical threat insights across the Cyber division, including the SOC Manager and Global Cyber Security Head.
- Developing and maintaining playbooks for Incident Response workflows.
- Enhancing processes through automation to improve efficiency.
- Supporting SOC Management in developing key performance indicators.
- Coordinating with Information Security teams to clarify risks and responsibilities during Incident Response.
- Leading structured threat hunts and refining them into repeatable processes.
- Mentoring Tier 1 & Tier 2 analysts through training and lessons learned.
- Driving continuous improvement in SOC operations and cybersecurity strategy.
- Staying updated on best practices in cybersecurity and Incident Response to recommend enhancements.
- Conducting and refining threat hunts regularly.
Requirements
Must-Haves:
- Passion for Cybersecurity:
Demonstrable commitment to ongoing learning through labs, CTFs, or contributions to the cyber community.
- Technical Proficiency:
- Extensive experience in TCP/IP protocol analysis.
- Solid skills in network management, monitoring tools, and utilities.
- Fluent in creating SIEM rules and searches to detect TTPs (not just IOCs).
- Experience:
- 6+ years in SOC, Incident Response, or equivalent experience (e.g., Bachelor's in Computer Science, Information Systems, or military background).
- Proven ability to conduct and refine threat hunts.
- Communication: Exceptional skills in conveying technical concepts to peers, management, and stakeholders.
Nice-to-Haves:
- Familiarity with cybersecurity frameworks (NIST, MITRE ATT&CK;, SANS, etc.).
- Experience in malware analysis, forensics, or consulting on security projects.
- Relevant certifications in Incident Response.