Responsibilities
- Monitor, triage, and respond to security alerts and events related to cyber threats, intrusions, and system compromises on a daily basis.
- Evaluate security events using tools like SIEM and EDR to determine risk levels and escalate critical incidents to incident response teams following defined protocols.
- Work with external teams to resolve incidents and manage escalation workflows effectively.
- Alert team leads to operational concerns such as unusual metric trends, active incidents, quality issues, or potential risks, and assist in resolving them when needed.
- Handle assigned cases through the full incident lifecycle, including analysis, containment, eradication, recovery, and post-incident review, while maintaining resolution quality.
- Keep detailed records of each security incident, including investigative notes, findings, containment actions, and root cause.
- Provide timely updates to stakeholders, communicate with affected users, and ensure proper documentation and handover during shift changes.
- Use expertise in security operations to refine and enhance playbooks, SOPs, and training resources.
- Support management by recommending improvements or adjustments to detection use cases to strengthen organizational security.
- Be available for paid overtime when required due to operational demands.
Work Arrangement
Remote
Other
- Follows a 10x4 schedule from Wednesday to Saturday as part of a 24x7 global monitoring operation.
- Position supports a 24x7 global security monitoring function.