To protect organizational assets and maintain business continuity by driving end-to-end incident management—rapidly detecting, triaging, containing, and remediating cybersecurity incidents, minimizing impact, and leveraging post-incident root cause analysis to continuously strengthen resilience.
- Lead and support security incident investigation, including digital forensics, malware analysis, root cause analysis, and threat remediation activities.
- Proactively identify, investigate, and mitigate security threats through log analysis, threat hunting, vulnerability assessment, and security analytics.
- Develop, optimize, and maintain security detection use cases, correlation rules, and response playbooks based on threat intelligence, attack techniques, and security requirements.
- Enhance the security operations to ensure continuous monitoring, threat detection, and timely response to security events.
- Continuously improve security operational efficiency through automation, process optimization, and adoption of security best practices and industry frameworks.