Overview
A security operations function is strengthening its detection and incident response capability and needs an experienced analyst for a hands on assignment. The role combines investigation of alerts with improvements to monitoring coverage, response procedures and security reporting.
Responsibilities
- Investigate security alerts and determine appropriate response actions.
- Improve detection coverage across endpoint and cloud environments.
- Document incidents and contribute to post incident reviews and response procedures.
- Work with the security team to improve monitoring quality and operational reporting.
Requirements
- 4+ years in cyber security operations or incident response.
- Experience investigating security events across endpoints and cloud environments.
- Strong understanding of SIEM platforms and alert triage.
- Familiarity with common attack techniques and defensive controls.
- Ability to document incidents clearly and support post incident reviews.
- Experience with Microsoft Sentinel or a comparable SIEM is preferred.
