Responsibilities
- Design and enhance detection and alerting controls to improve accuracy and reduce false positives, enabling faster response.
- Develop, test, and automate incident response playbooks and runbooks to boost efficiency and consistency throughout incident handling.
- Prioritize alerts using a scalable, data-driven triage method based on business impact and threat severity.
- Conduct thorough investigations, including root cause analysis and digital forensics, and translate findings into actionable improvements for detection and resilience.
- Actively participate in threat intelligence and hunting to identify new tactics, techniques, and procedures, and integrate insights into detection systems.
- Manage incidents from detection to resolution, collaborating with engineering, IT, and business teams to contain, eradicate, and recover from threats.
- Define and track operational metrics for incident response, using them to improve speed, accuracy, and organizational preparedness.