รายละเอียดงาน1. Monitor security alerts and events from SIEM systems, IDS/IPS, firewalls, endpoint protection platforms, and other security tools.
2. Conduct real-time analysis of security alerts to identify potential threats and vulnerabilities.
3. Develop and refine security monitoring use cases, correlation rules, and incident response playbooks.
4. Utilize AI-driven security analytics and automation tools to detect and mitigate threats more efficiently.
5. Investigate and respond to security incidents, ensuring proper documentation and escalation as required.
6. Perform forensic analysis on compromised systems to determine the root cause of security breaches.
7. Conduct threat hunting activities to proactively detect potential security risks.
8. Coordinate with IT and security teams to contain and remediate security incidents.
9. Assist in security compliance initiatives and audits by ensuring proper logging, monitoring, and reporting practices.
10. Provide recommendations to enhance security policies, controls, and risk mitigation strategies.
11. Support security awareness programs by educating employees on cybersecurity best practices.
12. Work closely with IT, DevOps, and security teams to implement infrastructure security upgrades and improvements.
13. Stay updated with the latest cybersecurity trends, threat intelligence, and attack methodologies.
14. Research and implement cutting-edge security technologies, including automation and AI-driven threat detection solutions.