- Incident Monitoring: Monitor and assess security alerts from systems like SIEM, IDS/IPS, and EDR, escalating as needed.
- Triage and Analysis: Investigate incidents to determine scope, impact, and root causes, documenting findings and actions.
- Incident Response: Contain, eradicate, and recover from threats in coordination with IT and security teams.
- Forensics: Perform digital forensics and ensure proper evidence collection for potential legal actions.
- Documentation and Reporting: Maintain records, create incident reports, and suggest improvements to policies.
- Collaboration: Work with IT, legal, and compliance teams; provide clear incident updates to stakeholders.
- Continuous Improvement: Conduct post-incident reviews and refine response procedures and playbooks.
- Policy Development:
Contribute to the creation and update of response playbooks and security training programs.
Key Skills & Knowledge:
- Bachelor's degree in Computer Science, Cybersecurity, or related field.
- 5+ years of experience in cybersecurity and incident response.
- Robust analytical skills to handle incidents and recommend remediation.
- ITIL Foundation certified; experience in regulated environments.
- Excellent communication and organizational skills.
Key Contacts:
- SOC, IT Operations, Threat Intelligence, and Forensic teams.
- Legal, Compliance, Risk Management, and external vendors.