Tasks and Responsibilities
- Work with the management team on all cybersecurity systems such as: Firewall, WAF, SIEM, AV, EDR, Proxy.
- Continuous monitoring of security alerts and incidents. Classify incidents into appropriate categories.
- Take actions based on the severity of the event, such as:
- Notifying system administrators.
- Following the incident response plan.
- Escalating incidents according to incident response procedures.
- Properly documenting incidents.
- Document and report incidents.
- Resolve issues related to user requests.
- Stay updated on cyber threats and gather information about attackers.
- Create or update cases and use new applications and systems.
- Analyze reported cybersecurity events and incidents via the Cybersecurity Authority.
- Conduct regular vulnerability scans for internal IP addresses.
- Monitor system compliance with technical security standards for the systems approved by the IT management after evaluation.
- Coordinate with other departments during incident investigations.
- Prepare a monthly report summarizing the main incidents that have been addressed.
- Operate and maintain the latest available versions of cybersecurity systems.
Education
Bachelor’s degree in Information Security, Computer Science, or a related discipline (Master’s preferred).
Experience
5+ years of professional experience in cybersecurity engineering, security operations, or related roles.
Proven hands-on experience with Symantec security solutions (e.g., Symantec Endpoint Protection, DLP, or Email Security).
Demonstrated expertise in incident management, threat monitoring, and vulnerability assessment.
Certifications
Required: CISSP or CASP.
Preferred: CCNA, GSEC, or SCS.
Technical Skills
Proficiency with security technologies such as SIEM, IDS/IPS, EDR, AV, and network firewalls.
Familiarity with TCP/IP, networking fundamentals, and common security protocols.
Experience with scripting/automation tools (Python, PowerShell, or Bash).
Strong analytical, investigative, and problem-solving skills.