- Design and implement comprehensive information assurance and IT security solutions, including SIEM, DLP, Endpoint Security, Identity Management, and Vulnerability Management.
- Participate in the selection, evaluation, deployment, and management of enterprise security technologies such as firewalls, antivirus, intrusion detection/prevention systems, encryption, and remote access.
- Perform configuration, administration, and optimization of security systems and tools at client sites.
- Define, verify, and implement security controls and countermeasures in alignment with organizational policies and industry standards.
- Deliver security recommendations and reports to improve the organization’s security posture.
- Conduct security investigations,
incident response, and forensic analysis of violations and breaches; prepare detailed reports and summaries for management.
- Develop and maintain forensic tools, standards, and procedures to ensure consistent investigation processes.
- Perform threat management and modeling, identifying potential threat vectors and developing use cases for security monitoring.
- Analyze system logs, vulnerability scans, trace data, and firewall/server logs to detect anomalies and enhance security operations