Overview
Tasks and Responsibilities:
- Work with the management team on all cybersecurity systems such as: Firewall, WAF, SIEM, AV, EDR, Proxy.
- Continuous monitoring of security alerts and incidents.
- Classify incidents into appropriate categories.
- Take actions based on the severity of the event, such as:
- Notifying system administrators.
- Following the incident response plan.
- Escalating incidents according to incident response procedures.
- Properly documenting incidents.
- Document and report incidents.
- Resolve issues related to user requests.
- Stay updated on cyber threats and gather information about attackers.
- Create or update cases and use new applications and systems.
- Analyze reported cybersecurity events and incidents via the Cybersecurity Authority.
- Conduct regular vulnerability scans for internal IP addresses.
- Monitor system compliance with technical security standards for the systems approved by the IT management after evaluation.
- Coordinate with other departments during incident investigations.
- Prepare a monthly report summarizing the main incidents that have been addressed.
- Operate and maintain the latest available versions of cybersecurity systems.
Qualifications
Certificates: CISSP or CASPCCNAGESCSCS
Experience: 5 years or more