Monitor security events 24/7, analyzing alerts to identify suspicious activity, performing log correlation, identifying IOCs (Indicators of Compromise), and conducting investigations to determine the scope and impact of security threats.
Execute initial response according to established playbooks, including containment and remediation actions, and escalate in accordance with applicable procedures and SLAs.
Conduct proactive threat hunting to identify hidden threats through analysis of telemetry data, anomaly patterns, and attack techniques not yet detected by automated tools.
Operate SIEM, EDR/XDR, and security monitoring tools, ensure optimal log ingestion, create and optimize detection rules/use cases, and perform alert tuning to improve detection accuracy.
Document security incidents and investigation findings, and prepare incident reports. Maintain case notes and keep ticket systems up to date.
Data lowongan bersumber dari kalibrr. Tombol “Lamar” mengarahkan Anda ke halaman aslinya.