Job Description
Roles & Responsibilities
Monitor security alerts and logs from various sources to promptly detect and triage potential security incidents, prioritizing based on severity and impact.
Conduct in-depth investigations into security incidents, employing digital forensics techniques and tools to analyze evidence, identify root causes, and determine the extent of compromise.
Take immediate action to contain security incidents, prevent further unauthorized access, and eradicate malicious activity from affected systems and networks.
Perform forensic analysis on compromised systems, networks, and digital artifacts to gather evidence, reconstruct events, and support incident response efforts.
Proactively search for indicators of compromise (IOCs), anomalous behavior, and emerging threats within organizational environments to detect and mitigate potential security breaches.
Collaborate closely with cross-functional teams, including IT, security operations, legal, and senior management, to coordinate incident response activities and communicate effectively throughout the incident lifecycle.
Prepare detailed incident reports documenting findings, actions taken, and lessons learned from security incidents for internal stakeholders, regulatory compliance, and potential legal proceedings.
Conduct post-incident analysis and lessons learned sessions to identify areas for improvement in incident response processes, procedures, and controls.
Stay abreast of the latest cyber threats, attack techniques, and security technologies through ongoing training, knowledge sharing, and participation in industry forums and communities.
Ensure compliance with relevant regulatory requirements, industry standards, and organizational policies related to incident response, data protection, and cybersecurity.
Perform trend analysis on events and incidents to identify and characterize threats.
Conduct open-source research to identify commercial exploits or vulnerabilities, including Zero-Day threats, necessitating prompt response actions.
Prepare comprehensive formal reports and presentations tailored for both technical and executive audiences.
Configure and optimize software and hardware-based detection and prevention mechanisms.
Assist in Computer Defense Assistance Program (CDAP) missions as requested by clients.
Stay abreast of the latest cybersecurity threats, technologies, and best practices.
Collaborate with cross-functional teams to elevate the overall cybersecurity posture.
Maintain current knowledge of relevant compliance requirements and ensure adherence.
Mentor and provide guidance to junior team members.
Collaborate with external organizations and agencies to share threat intelligence and enhance collective cybersecurity capabilities.
Performs other duties and assignments as required.