Cybersecurity Detection Engineering
• Design, test and deploy detections in support of the monitoring and alerting on potential cybersecurity threats
• Adjust existing detections to minimize false positives while avoiding false negatives
• Find chances to improve detection capabilities and translate those chances into action
• Align detection capabilities to organizational risk tolerance
Cybersecurity Incident Response
• Take ownership of assigned cybersecurity events ensuring complete and accurate triage, containment and remediation action
• Partner with collaborators across digital and business operations to drive response actions and restore normal operations
• Identify cybersecurity incident root cause and recommend remediation actions to prevent recurrence
• Create and maintain complete and accurate documentation of assigned cybersecurity event investigation from initial detection through closure including root cause identification, business impact, response actions, final disposition and event classification
• Provide after-hours or on-call incident support as required
Readiness and Continuous Improvement
• Monitor threat intelligence, attacker techniques and industry trends to maintain awareness of relevant and emerging cyber threats
• Participate in tabletop exercises, training and post incident review to strengthen preparedness across the team and the organization
• Mentor junior analysts and actively contribute to the team knowledge base and operational maturity
• Recommend improvements to operational processes and documentation