Title: Technical Lead-Cybersecurity
Area(s) of responsibility
Role Summary
We are seeking an experienced L2 Security Incident Response Analyst to support Security Operations Center (SOC) activities, including threat monitoring, incident investigation, threat hunting, detection analysis, malware triage, and incident response. The ideal candidate will have hands-on experience with SIEM, EDR, cloud security monitoring, log analysis, and cyber threat detection, along with the ability to investigate and respond to security incidents across enterprise environments.
Key Responsibilities
- Monitor, investigate, and respond to security alerts and incidents generated from SIEM, EDR, IAM, Cloud Security, and security monitoring platforms.
- Perform detailed incident analysis, triage, containment, eradication, and recovery activities.
- Conduct threat hunting activities to identify suspicious behavior, advanced threats, and potential security breaches.
- Analyze logs, network traffic, endpoint activities, and cloud events to identify indicators of compromise (IOCs).
- Investigate malware, phishing, ransomware, insider threats, account compromise, and unauthorized access incidents.
- Correlate security events from multiple security tools and data sources to determine attack scope and impact.
- Escalate critical incidents and coordinate with infrastructure, cloud, application, and business stakeholders during incident response activities.
- Create and maintain SIEM correlation rules, use cases, detection logic, and alert tuning recommendations.
- Support forensic investigations and root cause analysis.
- Prepare incident reports, executive summaries, and post-incident review documentation.
- Validate security controls and recommend improvements to detection and response capabilities.
- Participate in vulnerability remediation validation and risk reduction activities.
- Support security audits, compliance initiatives, and governance requirements.
- Develop and maintain SOC runbooks, playbooks, and operational procedures.
- Assist in continuous improvement of SOC processes, threat detection, and response capabilities.
Required Skills
- Security Incident Monitoring & Response
- SIEM Operations & Analysis
- Threat Hunting
- Incident Investigation & Triage
- Malware Analysis Fundamentals
- IOC Analysis & Threat Intelligence
- Endpoint Detection & Response (EDR/XDR)
- Log Analysis & Event Correlation
- Network Security Monitoring
- Cloud Security Monitoring
- Email Security & Phishing Analysis
- Vulnerability Management Fundamentals
- Digital Forensics Concepts
- MITRE ATT&CK Framework
- Cyber Kill Chain Methodology