Source description
About the role
• Architecting and implementation of cloud security monitoring platforms Azure Sentinel (SIEM), Defender (EDR/XDR), SentinelOne(EDR), Email Security Solutions • Perform as the subject matter expert on Cloud Security solutions for the customer and use the solution's capabilities in the daily operational work for the end customer. • Vulnerability Management: Support delivery of the vulnerability management program, including vulnerability scanning, vulnerability assessments, and tracking support for vulnerability remediation • Securing overall environments by applying cybersecurity tools and best practices • Expertise in Azure Sentinel and Defender • SOC operations, technology support and maintenance • Develop and maintain SOC playbooks, standard operating procedures (SOPs), and response plans to ensure efficient and incident response. • Lead incident response efforts during security breaches or cyber incidents, coordinating with internal teams and external stakeholders to contain and resolve incidents promptly. • Evaluate, select, and implement security tools and technologies to enhance the capabilities of the SOC. • Configure and tune security tools to optimize performance, detection accuracy, and minimize false positives. • Evaluate SOC policies and procedures and recommend updates to management as appropriate. • Monitor SIEM/XDR and AV/EDR solutions for attacks, intrusions, and unusual, unauthorized, or illegal activity. • Monitor and respond to 'phishing' emails, Fraud s spam, and unwanted or malicious emails. • Provide strategic direction and visionary leadership for comprehensive IT security functions, covering cloud, DevOps, infrastructure, network, application, and data security. • Execute vulnerability assessments, penetration tests, and security audits to identify and mitigate risks and weaknesses. • Formulate, implement, and enforce robust IT security policies and procedures that align with industry standards and best practices. • Security audit and framework (ISO 27001, NIST, PCI-DSS) and Ability to perform Internal Audits for different teams • Industry standard certifications like CISSP, CISM, and CISA are considered a plus
Security knowledge SOC team management Security monitoring Team management Stakeholder management
More at Bahwan CyberTek