Strengthen enterprise security operations by focusing on protecting our corporate infrastructure through advanced threat detection, incident response, and security operations. You will work with cutting-edge SIEM, SOAR, and zero-trust technologies to defend against evolving threats. Manage and optimize Sumo Logic SIEM for threat detection and investigation. Implement and maintain Netskope SASE/ZTNA solutions for zero-trust security and conduct threat hunting using Recorded Future threat intelligence and YARA rules.
Develop and maintain detection rules and correlation logic in SIEM, orchestrate security operations using Tines SOAR platform. Manage CrowdStrike EDR deployment and incident response and lead incident response activities as required. Analyze security events, conduct forensic investigations, develop and maintain security runbooks and automation playbooks. You will also monitor and respond to security alerts 24/7 through established procedures.