Responsibilities:
• Continuously monitor security alerts and system logs to identify potential threats and anomalous activity across the OA DCGS weapon system, ensuring its confidentiality, integrity, and availability.
• Utilize ELK/Elastic Stack to conduct real-time log analysis, detect threats, and support investigations; maintain dashboards and incident records for visibility and reporting.
• Escalate and document security events using established ticketing systems, ensuring timely and accurate reporting to internal cyber analyst tiers (T1–T3) and appropriate external stakeholders beyond the Incident Response (IR) team.
• Follow and maintain cybersecurity standard operating procedures (SOPs) and incident response playbooks to ensure consistent and effective monitoring practices.
• Maintain detailed documentation of monitoring activities, incident timelines, and case notes to support post-incident reviews and compliance requirements.
• Contribute to proactive threat detection by reviewing SIEM alerts and security dashboards to identify indicators of compromise (IOCs) and anomalous activity, supporting early escalation through behavioral analysis and correlation techniques.
• Monitor threat intelligence feeds and security news for emerging threats, including Zero-Day vulnerabilities and CVEs, and escalate relevant findings to senior analysts for integration into detection workflows.
• Collaborate with incident response, threat hunting, and vulnerability management teams to ensure seamless handoff and resolution of detected threats.
• Operate independently during assigned shifts, responding to alerts with urgency and precision to minimize potential impact.
• Support penetration testing evaluations by responding to simulated threats in real time, enabling measurement of key performance indicators (KPIs) such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR)