About the role
Monitor, investigate, and respond to security alerts and incidents across multiple enterprise security platforms. Perform advanced security event analysis, incident triage, threat investigation, containment, remediation, and root cause analysis. Correlate security events across SIEM, EDR, email security, firewall, identity, and other security technologies. Administer, configure, maintain, and troubleshoot enterprise security tools and security controls.
Key responsibilities
- Investigate suspicious endpoint activities, authentication events, network traffic, malicious emails, and other potential security threats
- Lead or support security incident response activities and coordinate remediation with Infrastructure, Network, Systems, and IT Support teams
- Manage and support Privileged Access Management (PAM) solutions, particularly BeyondTrust
- Support CrowdStrike security operations and related security workflows
- Manage vulnerability remediation and Patch Management activities for servers and endpoints
- Coordinate security patch deployment, maintenance windows, system reboots, post-patch validation, troubleshooting, and remediation
- Track vulnerabilities and patch compliance and ensure identified security risks are addressed within established timelines
- Develop and improve security monitoring rules, operational procedures, incident response processes, and security documentation
- Identify gaps in existing security controls and recommend technical improvements
- Provide senior-level technical guidance and mentoring to Security Analysts and other members of the IT organization
About you
- Minimum 5+ years of professional experience in Cybersecurity, Security Engineering, Security Operations, or a related field
- Strong hands-on experience investigating and responding to security incidents in enterprise environments
- Strong knowledge of SIEM, EDR/XDR, endpoint security, network security, email security, and identity/access security
- Solid understanding of Windows Server, Active Directory, networking, authentication, and enterprise infrastructure
- Experience with vulnerability remediation and enterprise patch management
- Ability to analyze logs, processes, network activity, authentication events, and endpoint telemetry to determine whether activity is legitimate, suspicious, or malicious
- Strong troubleshooting and root cause analysis skills
- Ability to independently manage security incidents and technical security issues from investigation through resolution
- Strong documentation, reporting, and communication skills
- Ability to collaborate effectively with Infrastructure, Network, Systems, IT Support, and other technical teams