Coordinate the investigation, containment, recovery, and remediation of cybersecurity incidents, collaborating with IT, legal, communications, and third parties as neededServe as the primary contact during incidents, providing status updates and coordinating activities with leadership, internal teams, and external partnersMonitor and analyze network traffic, security logs, and alerts to identify, triage, and respond to suspicious activity and potential incidentsDocument after action incident details, actions taken, timelines, and lessons learned in line with organizational standardsConduct periodic incident response exercises, deliver training, and raise awareness among staff on emerging threats and protocolsCollect intrusion artifacts (e.g., source code, malware, trojans) and use discovered data to enable mitigation of potential cyber defense incidents within the enterpriseContinuously review and improve the incident response plan, procedures, and playbooks based on post-incident reviews and lessons learnedPerform initial triage and analysis of security incidents to assess scope, urgency, and impact.Guide cross-functional teams to contain threats, eradicate vulnerabilities, and restore normal operationsCoordinate with the Corporate Leadership, Security Operations Center (SOC), and external parties as requiredLead after-action reviews, publish findings, and recommend mitigation measures to strengthen future defensesStay current with evolving threats, vulnerabilities, and best practices through threat intelligence monitoring and external sourcesStrong knowledge of incident response processes, attack vectors, threat tactics, and detection methodsExperience with DNS Security, SIEM and SOAR systems, endpoint detection tools, forensic software, and security monitoring solutionsExcellent analytical, problem-solving, and communication skills, with the ability to perform under pressureFamiliarity with regulatory requirements, security frameworks, and incident response standards (e.g., NIST, ISO 27001)Proactive mindset focused on continuous improvement, training, and cross-departmental collaborationBachelor s degree in computer science, Information Technology, Cybersecurity, or a related field or equivalent work experience of 5 years or moreMinimum of 2 years of experience in cybersecurity incident response or a related roleSkills Required
Siem Tools, Cybersecurity, Problem Solving Skills