What you will be doing:
? Perform thorough analysis of cybersecurity alerts, assuming complete responsibility for leading and concluding the investigation. Leveraging our strategic partnership with an external entity, initial triage has been completed, focusing your attention on investigating only the more complex and challenging alerts.
? Utilize cutting-edge technology for security investigations, such as EDR, SIEM, SOAR, and other advanced tools.
? Maintain a continuous communication loop with the outsourced staff of the frontline defense center and the external segments of the cyber defense center. This ensures alignment, facilitates the exchange of knowledge, and promotes a seamless and effective collaboration.
? As a member of the regional cyber defense center, your role is crucial in maintaining proximity to operating companies. You support local IT and ISOs by addressing security issues and translating necessary information for analysis and response into actionable tasks.
? Play a key role in enhancing the CDC's ongoing improvement. After conducting each investigation, engage in additional analysis of the incident. Proactively suggest new playbooks when relevant. This guarantees optimal efficiency for both the cyber defense center and the cyber defense frontline in carrying out their tasks.
? In the role of a cyber defense engineer, your daily responsibilities will extend to providing support for various operational tasks. During available time and depending on your skills and interests, you will aid the vulnerability management lead and the threat intelligence lead in their respective operations.
? You will work closely with the continuous improvement lead to design and develop new and improve existing threat detection capabilities. This involves contributing to the threat modeling program to identify gaps in security controls and specifying the necessary security controls and monitoring requirements.
? During critical security incidents, you'll join forces with the CSIRT to swiftly and decisively bring closure to these challenges, ensuring a resilient and secure environment.