We are seeking an experienced Security Engineer to join our team. You will be responsible for real-time monitoring and analysis of security events, implementation and optimization of SIEM solutions, threat intelligence analysis, incident response development, and collaboration with various teams to improve organizational security posture. This role requires a strong background in cybersecurity, hands-on experience with SIEM tools, and excellent analytical and communication skills.
Key Responsibilities:
- Real-time monitoring and analysis
- Continuously monitor security alerts and events from multiple security tools and systems within the SOC.
- Analyze security incidents to assess severity and potential impact on the organization.
- Use advanced analytics and threat detection techniques to identify anomalies and suspicious activities.
- SIEM implementation and optimization
- Lead the deployment and configuration of Security Information and Event Management (SIEM) solutions.
- Fine-tune SIEM rules and alerts to reduce false positives and improve detection capabilities.
- Regularly review and update SIEM configurations to adapt to evolving threats and organizational changes.
- Threat intelligence analysis
- Collect, analyze, and disseminate threat intelligence from open-source, commercial, and internal sources.
- Correlate threat intelligence with security events to provide context and enhance incident response.
- Stay current with the latest threat trends, vulnerabilities, and attack vectors relevant to the organization.
- Incident response development
- Develop and maintain comprehensive incident response playbooks for various types of security incidents.
- Conduct tabletop exercises and simulations to test and refine incident response plans.
- Coordinate with cross-functional teams during incidents to ensure effective containment and remediation.
- Collaboration and security posture improvement
- Work closely with IT, network, and application teams to identify security gaps and recommend improvements.
- Participate in security assessments, audits, and vulnerability management processes.
- Share insights and findings with stakeholders to promote security awareness.
- Reporting and presentation
- Prepare detailed reports on security incidents.
- Present findings and trends to management and other stakeholders, highlighting areas for improvement.