Roles and Responsibilities :
- Security Tool Management : Administer, configure, and maintain enterprise security tools including SIEM, vulnerability management, endpoint protection, and threat intelligence platforms.
- Integration & Optimization : Integrate security tools with existing infrastructure and optimize performance to ensure seamless data flow and effective threat detection.
- Incident Response Support : Collaborate with SOC and Incident Response teams to enhance detection capabilities and fine-tune security use cases.
- Automation & Scripting : Develop and maintain automation scripts or workflows using tools such as Python, PowerShell, or REST APIs to improve operational efficiency.
- Policy & Compliance Alignment : Ensure all tools and configurations comply with organizational security policies, regulatory requirements, and industry best practices.
- Monitoring & Reporting : Generate detailed reports and dashboards to provide insights into security posture, tool performance, and incident trends.
- Tool Evaluation & Implementation : Evaluate emerging security technologies and recommend suitable tools to strengthen the organization's defense ecosystem.
- Collaboration & Mentoring : Work closely with cross-functional teams including network, infrastructure, and application teams. Mentor junior engineers on tool usage and best practices.
Skills Required
Vulnerability Assessment, Penetration Testing, Incident Response, Threat Hunting