Posted on: 03/06/2026
Role and Responsibilities :
Incident Response and Collaboration :
- Collaborate with SOC, CERT, or CSIRT teams for effective incident monitoring and response.
- Investigate and respond to cybersecurity incidents, including forensic analysis of attack patterns.
SIEM Administration :
- Provide ongoing support for SIEM Architecture, ensuring efficient log ingestion, parsing, and normalization to enhance threat visibility and detection capabilities.
- Design and customize automated playbooks and interactive dashboards in SIEM to meet specific security monitoring and incident response requirements.
Threat Intelligence Analysis :
- Gather, process, and analyze threat intelligence feeds to identify emerging threats.
- Proactively communicate relevant threat scenarios and provide actionable insights.
Threat Detection Development :
- Develop and fine-tune advanced KQL queries and analytics rules in Microsoft Sentinel to detect sophisticated attack vectors.
- Build and test hypothetical threat scenarios to enhance threat detection capabilities.
- Optimize detection systems to minimize false positives and maximize precision.
Security Tool Management :
- Configure, monitor, and maintain security tools such as SIEM (Microsoft Sentinel), Defender for Cloud, antivirus solutions, and consolidated security dashboards.
Continuous Improvement :
- Participate in developing and implementing security concepts, hardening guidelines, and monitoring systems.
- Perform penetration tests, vulnerability assessments, and audits to ensure robust security measures.
- Contribute to the creation and refinement of SOC policies, processes, and procedures.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1641241