Security Monitoring & Incident Response
• Oversee and respond to alerts from AWS GuardDuty, ensuring timely investigation and remediation of incidents.
• Execute security playbooks to handle alerts, and enhance them based on evolving threats and operational insights.
Vulnerability & Patch Management
• Coordinate the identification and application of security patches across GitLab, AWS, and Kubernetes components.
• Ensure that our infrastructure remains resilient to new vulnerabilities through regular patch cycles and proactive risk assessments.
Log Analysis & SIEM Management
• Conduct weekly SIEM reviews to analyze security logs, detect anomalies, and escalate issues as necessary.
• Collaborate with the SecOps team to refine monitoring strategies and alerting thresholds.
Reporting & Documentation
• Prepare monthly SecOps reports summarizing incident trends, response actions, and areas for improvement.
• Maintain and update documentation related to security processes, incident response, and playbooks.
Collaboration & Continuous Improvement
• Work closely with development, operations, and other security teams to integrate security best practices into CI/CD pipelines and cloud deployments.
• Proactively contribute to security strategy discussions, sharing insights and recommendations for enhanced security posture.