As a Cybersecurity Expert, you will join our team in the CISO organization to contribute to daily security incident preparation, detection, and response activities. Your role includes threat detection, incident handling, and threat hunting.
You will work closely with other members of the SOC, CSIRT, and other teams within the organization to identify and mitigate security risks. You will also develop and implement incident response plans and procedures, and provide guidance to other members of the organization on security best practices.
Additionally, you will be responsible for threat detection and hunting, using your expertise in security operations to proactively identify threats and vulnerabilities within the organization's infrastructure. This involves conducting regular threat hunting exercises to detect potential threats that may have evaded detection by traditional security measures.
You will use a variety of tools and techniques to collect and analyze security data to identify anomalous behavior and potential indicators of compromise.
Furthermore, you will play a critical role in ensuring the organization's security posture remains strong by developing, maintaining, and optimizing our SIEM systems to ensure timely detection and response to security incidents.
This includes creating and maintaining use cases and detection rules based on the MITRE ATT&CK framework, as well as writing playbooks for the SOC team to ensure consistent and effective incident response.
Automating the response to SIEM and EDR events is also essential to allow the SOC and the CSIRT to focus on the essentials.
Next to the core business of our team activities, you will also contribute to different projects based on the needs of our team. This can include rolling out new products or platforms, maintaining them, and automating manual tasks with the help of scripts, etc.