Primary Responsibilities
Incident Monitoring: Monitor and assess security alerts from systems like SIEM, IDS/IPS, and EDR, escalating as needed.
Triage and Analysis: Investigate incidents to determine scope, impact, and root causes, documenting findings and actions.
Incident Response: Contain, eradicate, and recover from threats in coordination with IT and security teams.
Forensics: Perform digital forensics and ensure proper evidence collection for potential legal actions.
Documentation and Reporting: Maintain records, create incident reports, and suggest improvements to policies.
Collaboration: Work with IT, legal, and compliance teams; provide explicit incident updates to stakeholders.
Continuous Improvement: Conduct post-incident reviews and refine response procedures and playbooks.
Policy Development:
Contribute to the creation and update of response playbooks and security training programs.
Key Skills & Knowledge:
Bachelor's degree in Computer Science, Cybersecurity, or related field.
5+ years of experience in cybersecurity and incident response.
Robust analytical skills to handle incidents and recommend remediation.
ITIL Foundation certified; experience in regulated environments.
Excellent communication and organizational skills.
Key Contacts:
SOC, IT Operations, Threat Intelligence, and Forensic teams.
Legal, Compliance, Risk Management, and external vendors.