1. Lead and coordinate the response to security incidents, including triage, investigation, analysis, and communication.
2. Develop and maintain incident response playbooks and runbooks for threat scenarios.
3. Automate and optimize detection, incident analysis, and response workflows.
4. Improve security detection capabilities through rule development and proactive threat hunting.
Role Responsibilities:
1. Conduct root cause analysis of incidents and suggest improvements to processes.
2. Collaborate across teams to implement security measures and mitigation strategies.
3. Provide expert input on the design and implementation of security controls and automation tools.
4. Analyze and correlate large sets of security data to identify anomalous activity.