Responsibilities
- Manage the team responsible for monitoring, identifying, and responding to cybersecurity incidents.
- Motivate, mentor, and grow team members by promoting teamwork and ongoing skill development.
- Supervise daily operations of security platforms including Rapid7/InsightIDR, QRadar, FortiSIEM, and Microsoft Sentinel, along with tools such as EDR, SOAR, firewalls, and IDS/IPS systems.
- Establish, evaluate, and update incident response playbooks, security policies, and key performance indicators to enhance operational effectiveness.
- Provide hands-on support during high-priority investigations, performing technical analysis and contributing to strategic decisions with the team.