Source description
About the role
Job description Utilize SIEM tools such as IBM QRadar, EDR solutions, and antivirus software for security event monitoring and incident response. Lead and manage the SOC team, providing guidance and training to L1 and L2 analysts. Perform deep dive investigations into security incidents and provide detailed analysis. Ensure 24/7 availability to respond to security incidents and manage incident response processes. Develop and integrate use cases and log sources into IBM QRadar. Handle client escalations and maintain strong client relationships. Create and present governance reports, lead cyber drills, and generate actionable insights. Stay updated on MITRE tactics and techniques, and understand the cyber kill chain. Communicate effectively with clients, both verbally and in writing. Travel as needed to meet with clients and provide on-site support. 6-8 years of experience in security operations, incident response, and incident management. Proficiency in using SIEM tools, EDR solutions, and antivirus software. Strong knowledge of firewalls, proxies, DLP, DNS, WAF, and other networking protocols. Experience in handling client escalations and working in client-facing roles. Good understanding of MITRE tactics and techniques, and the cyber kill chain. Ability to create use cases and integrate log sources into IBM QRadar. Experience in creating governance reports and leading cyber drills. Self-motivated with the ability to work independently and as part of a team. Excellent communication skills, both verbal and written. Prior experience in the banking, insurance, or finance sectors is a plus.
More at Aujas Cybersecurity An NSEIT Company