Work in a 24/7 Global SOC Team that operates in three shifts Conduct preliminary incident triage according to the Security Incident Management Triage Matrix and set the priority, provide analysis, determine, track remediation, and escalate as appropriate.
Utilize the intrusion detection, security scanning, security log collection, content filtering, and other security-related systems to perform triage and investigation and incident response.
Provide support for security incidents coordination, by using different communication means.
Ensure the SOC team documentation is up to date, including Investigation Playbooks and Standard Operating Procedures as well incidents have current notes related to investigation steps which were performed.
Categorization and prioritization of security incidents Looking for the correlation between various security events.
Monitor security incidents for, endpoints, network, and cloud domains, being generated by the SIEM tool and ticketing system.
Initial triage and investigation of incidents assigned through the ticketing system, following established playbooks for specific incident types.
Provide consistent and quality documentation of actions taken to triage / investigate incidents.
Education - Degree in Computer Science, Engineering, Information Systems, or Cyber Security or equivalent degree – OR – 6 years equivalent