Job Description:
Monitor security events and alerts using SIEM, SOAR, EDR, NDR, and other security platforms. Take proactive and reactive actions to detect, analyze, and mitigate security attacks and threats. Coordinate with internal team members, management, L3 support, and vendors to investigate, document, and report security incidents. Provide Root Cause Analysis (RCA) for service and security incidents with alignment with L3 support and vendors. Regularly review existing security policies, controls, and configurations, and recommend enhancements as needed. Ensure documented processes, playbooks, and procedures are accurate, relevant, and up to date. Create and maintain high-quality documentation for incidents, changes, standard operating procedures, and runbooks. Automate security operations processes using scripts and orchestration platforms to improve efficiency and response time. Provide proactive and real-time guidance to customers on: Network security configuration; Security protocols; Defensive security response and best practices; Support threat hunting activities and continuous security posture improvement. Participate in security testing, validation, and attack simulation exercises. Stay updated with emerging threats, vulnerabilities, and security technologies.