Job Duties and Responsibilities:
- Detects, identifies, and responds to cyber events, threats, security risks, and vulnerabilities in line with cyber security policies and procedures
- When necessary, lead and coordinate incident response investigators and stakeholders, and security operations center team to effectively investigate and neutralize a security incident
- Identifies, documents, and blocks TTPs, IOCs, and other artifacts during incident response
- Full JD attached
Skills Needed:
- Experience working in a SOC a must
- Experience/Familiarity with the following: Splunk, Palo Alto, Crowd Strike, Dark Trace, Service Now, Proof Point
- Scripting a plus (Python, PowerShell)
- Important: Because of the structure of the team/env., the person needs to be able to work tickets (malware, phishing, etc.) and cannot think the work is beneath them