Objective of job (abbreviated)
To protect organizational assets and maintain business continuity by driving end-to-end incident management—rapidly detecting, triaging, containing, and remediating cybersecurity incidents, minimizing impact, and leveraging post-incident root cause analysis to continuously strengthen resilience.
• Lead and support security incident investigation, including digital forensics, malware analysis, root cause analysis, and threat remediation activities.
• Proactively identify, investigate, and mitigate security threats through log analysis, threat hunting, vulnerability assessment, and security analytics.
• Develop, optimize, and maintain security detection use cases, correlation rules, and response playbooks based on threat intelligence, attack techniques, and security requirements.
• Enhance the security operations to ensure continuous monitoring, threat detection, and timely response to security events.
• Continuously improve security operational efficiency through automation, process optimization, and adoption of security best practices and industry frameworks.
Qualification
Technical Skills and Knowledge:
-Comprehensive experience in cyber security incident response process and handling.
-Hands-on experience with at least one SIEM platform, such as: Splunk, IBM QRadar, Elastic Stack for rapid event correlation, threat containment, and remediation.
-Experience with one or more of the following security tools: EDR, IDS / IPS, WAF, Firewalls.
-Strong log analysis skills, including: Windows Event Logs, EDR Logs, Network traffic logs, Cloud security logs.
-Better with experience in digital forensics to determine root cause.
-Proficiency in scripting languages such as Python or Shell for security automation.
-Relevant certifications, GCIH, GCFA, GREM, OSCP
> 3 years experience in security operations, incident response, threat detection and analysis, or similar roles
Education: Bachelor's degree and above in Computer Science encompassing Information Security
