Design, implement, integrate, and maintain our core security operations infrastructure, including the SIEM (Security Information and Event Management), EDR (Endpoint Detection and Response), CSPM (Cloud Security Posture Mgmt.), and network and vulnerability scanners. * Log & Data Engineering: Ensure the reliable collection, parsing, and normalization of security logs from all critical systems (cloud, network, endpoints) into the SIEM for effective analysis and alerting. * Threat & Vulnerability Management: Proactively hunt for threats and vulnerabilities across our network, cloud infrastructure, endpoints, and applications. Perform deep-dive incident investigation & triage, containment, and root cause analysis across endpoints, network, and cloud environments. * Strong understanding of network protocols, operating systems (Windows, Linux), and common security threats and attack vectors.
mehr