Job Responsibilities
Perform continuous monitoring and triage of security events and alerts generated by SIEM, EDR, NDR, IDS/IPS, firewalls, and cloud security environments.
Investigate suspected cybersecurity alerts, conduct root-cause analysis, and initiate incident response playbooks for containment, eradication, and recovery.
Actively hunt for hidden adversaries, analyze indicators of compromise (IOCs), and integrate real-time threat intelligence feeds into detection systems.
Create, maintain, and test security monitoring use cases, detection rules, and automated SOAR response playbooks.
Prepare detailed incident reports, compile operational security metrics for dashboards, and actively participate in cyber simulation drills and forensics.
Hands-on experience configuring and analyzing SIEM logs (Splunk, QRadar, Microsoft Sentinel, etc.), EDR solutions, and firewall rule behaviors.
Data lowongan bersumber dari jobstreet. Tombol “Lamar” mengarahkan Anda ke halaman aslinya.