Responsibilities
- Monitor and respond to security events and incidents using established incident response plan/runbook and creating process and procedures where none are already established.
- Recognizing potential, successful, and unsuccessful intrusion attempts and compromises thorough reviews and analyses of relevant event detail and summary information.
- Work on escalated security incidents (malware infections, unauthorized access, malicious emails, Phishing, Distributed Denial of Service (DDoS) attacks, etc.)
- Coordinating with stakeholders with supporting third party security service providers to triage alerts, events or incidents.
- Creation of SIEM custom detection rules to identify suspicious cyber threats or anomaly activities.
- Experience in responding to security events, including front-line analysis and escalation, on hacktivist, cybercrime, and APT activity.
- Support cyber incident response plan/lifecycle to ensure proper assessment, containment, mitigation and documentation.
- Reviews incident data and provide root cause analysis and recommendations on how to prevent future occurrences
- Identify coverage and efficiency gaps in IR runbook, security data and response tooling.
- Be on standby rotation, responding to high severity incidents escalated by cyber security operations analysts.
The Ideal Candidate Should Possess
- Degree/Diploma or higher in Computer Science, Information Systems or equivalent
- At least 2 years of experience in cyber security operations or SOC environment.
- Proven and hands on experience in area of SIEM, IDS/IPS, EDR, data leakage prevention (DLP) and SOAR.
- Strong knowledge of various automated security control systems, encryption, message authentication, vulnerability assessment, threat intelligence intrusion detection, penetration testing and incident response.
- Good knowledge in Incident response lifecycle, different Operating Systems, TCP/IP networking and application layers.
- Professional security related qualification (e.g. SANS GCIA, GSEC, GCIH) will be favourable although not mandatory