Job Description
Make An Impact By
- Act as the Enterprise Cyber Security technical focal point during cyber incidents, working closely with SOC, CISO, infrastructure, network, cloud, application, and vendor teams.
- Support cyber incident response activities including triage, investigation, containment coordination, evidence gathering, remediation tracking, and post incident review.
- Conduct proactive threat hunting across Enterprise infrastructure using available telemetry from SIEM, EDR, NDR, vulnerability management, asset discovery, and other security tools.
- Identify suspicious behaviours, attack patterns, lateral movement indicators, privilege misuse, exposed services, anomalous access, and other signs of compromise.
- Develop and enhance threat hunting hypotheses, detection use cases, investigation playbooks, response procedures, and escalation workflows.
- Support improvement of security monitoring by identifying gaps in logs, telemetry, ...