Scope of Work:
- Operate within a 24/7 Security Operations Center (SOC) environment, ensuring round-the-clock coverage for security monitoring and incident response.
- Monitor alerts and notifications generated by security systems and tools, identifying potential security incidents.
- Investigate and analyze security alerts, discerning false positives from genuine threats, and escalating as per defined protocols.
- Collaborate with Tier-2 analysts and assist in incident response activities, contributing to effective containment and resolution.
- Follow established procedures for analyzing and escalating critical security incidents, adhering to response timelines.
- Monitor network and system logs, identifying suspicious activities and anomalies that could indicate security breaches.
- Assist in generating incident reports and documenting the analysis, actions taken, and outcomes for future reference.
- Participate in routine security assessments, such as vulnerability scans, and assist in evaluating results.
- Maintain awareness of current security threats and trends, staying informed about emerging attack techniques.
- Follow and document standard operating procedures for security monitoring and incident response.
- Contribute to continuous improvement efforts by suggesting enhancements to processes, tools, and procedures.
- Support security team members in creating and fine-tuning security use cases for better detection capabilities.
- Maintain a strong understanding of the organization’s network, systems, and applications to effectively identify anomalies.
- Assist in reviewing and analyzing threat intelligence reports to understand potential risks to the organization.
- Participate in training and skill development programs to enhance security knowledge and expertise.
Discover more from
Subscribe to get the latest posts sent to your email.
