Source description
About the role
Threat Monitoring: Continuously monitor network traffic, systems, and security logs for signs of suspicious or malicious activity Incident Detection: Detect and identify potential security incidents, including unauthorized access, malware infections, and data breaches Security Tools: Utilize security tools and technologies like SIEM (Security Information and Event Management), IDS/IPS (Intrusion Detection System/Intrusion Prevention System), and endpoint security solutions to monitor and analyze network activity Analysis and Investigation: Investigate security incidents to determine the scope, impact, and root causes This includes analyzing logs, network traffic, and system behavior Incident Response: Develop and execute incident response plans, which may involve isolating compromised systems, containing threats, and recovering from security incidents Security Reports: Prepare and maintain reports on security incidents, including incident details, impact analysis, and mitigation strategies
More at Pacific Cyber Technology