1. 10-12 years of Information Security experience with at least 5 years of direct Incident Management and Security Operations experience.
2. Proven experience leading Major Security Incident Management engagements within enterprise environments.
3. Experience managing client-facing cyber security operations and escalations.
4. Experience working within global SOC environments.
Technical Expertise
1. Solid understanding of Incident Management lifecycle, crisis coordination, and security operations processes.
2. Hands-on experience with:
- Microsoft Sentinel
- Cortex XSOAR
- Endpoint Detection & Response (Microsoft Defender, CrowdStrike, etc.)
- SIEM and Security Monitoring technologies
3. Strong understanding of MITRE ATT&CK; Framework,
Cyber Kill Chain, and NIST Incident Response Framework.
4. Understanding of threat intelligence and threat hunting concepts.
5. Profound knowledge in cloud security environments including Microsoft Azure and Microsoft 365.
6. Understanding of malware, attack techniques, and adversary tactics sufficient to coordinate response activities effectively.
7. Experience developing incident response playbooks and automation workflows.