Primary Responsibilities :
- Incident Monitoring : Monitor and assess security alerts from systems like SIEM, IDS/IPS, and EDR, escalating as needed.
- Triage and Analysis : Investigate incidents to determine scope, impact, and root causes, documenting findings and actions.
- Incident Response : Contain, eradicate, and recover from threats in coordination with IT and security teams.
- Forensics : Perform digital forensics and ensure proper evidence collection for potential legal actions.
- Documentation and Reporting : Maintain records, create incident reports, and suggest improvements to policies.
- Collaboration : Work with IT, legal, and compliance teams; provide clear incident updates to stakeholders.
- Continuous Improvement : Conduct post-incident reviews and refine response procedures and playbooks.
- Policy Development :
Contribute to the creation and update of response playbooks and security training programs.
Key Skills & Knowledge :
- Bachelor's degree in Computer Science, Cybersecurity, or related field.
- 5+ years of experience in cybersecurity and incident response.
- Solid analytical skills to handle incidents and recommend remediation.
- ITIL Foundation certified; experience in regulated environments.
- Excellent communication and organizational skills.
Key Contacts :
- SOC, IT Operations, Threat Intelligence, and Forensic teams.
- Legal, Compliance, Risk Management, and external vendors.