n
- Monitor multiple security technologies such as SIEM, Antivirus, Vulnerability management, Web Proxy, Security Patch management.
n
- Tune/Create SIEM correlation rules.
n
- Perform in-depth incident and event analysis.
n
- Respond and handle the security incidents.
n
- Agree and align on reporting and monitoring requirements with business stakeholders.
n
- Conduct research on emerging security threats.
n
- Modify Standard Operating Procedures (SOPs) and training documentation.
n
- Coach junior team members.
n
- Good Knowledge on SIEM tools like QROC, Arcsight, SPLUNK or Sentinel.
n
- Knowledge and experience with PCs,
LAN topologies, routers, hubs, and terminal servers
n
- Knowledge of security applications such as IDS, Security Event Management and anomaly detection tools.
n
- Knowledge of VPN technology.
n
- Knowledge of investigation tools like FTK imager, memory dump, threat analysis tools.
n
- Ability to read and interpret network diagrams.
n
- Oversight of facilitates for other offices in the UK and provide support and guidance where required.
n
- Ability to translate event analysis findings into recent monitoring proposals.
n