The posting
- Monitoring, evaluating, and managing cybersecurity incidents.
- Performing initial triage and determining alert severity.
- Investigating incidents through SIEM, EDR, and other telemetry sources.
- Containment, eradication, and remediation of confirmed threats.
- Collecting and preserving digital evidence with appropriate chain of custody.
- Analyzing logs, endpoints, network traffic, and suspicious files.
- Performing root-cause analysis and determining the scope of each incident.
- Conducting threat hunting based on techniques and indicators of compromise.
- Writing incident reports and proposing corrective actions.
- Participating in tabletop exercises and improving incident response playbooks.
Requirements
- At least 2 years of experience in SOC, Incident Response, or Digital Forensics.
- Experience using SIEM platforms such as Microsoft Sentinel, Splunk, or QRadar.
- Familiarity with EDR/XDR solutions such as Microsoft Defender or CrowdStrike.
- Good knowledge of Windows, Linux, and basic cloud environments.
- Ability to analyze system, network, and application logs.
- Good understanding of the Incident Response phases and MITRE ATT&CK.
- Basic knowledge of digital forensics and malware analysis.
- Experience in threat hunting and management of Indicators of Compromise.
- Knowledge of scripting with Python, PowerShell, or KQL will be considered an additional asset.
- GCIH, GCFA, SC-200, BTL1, or an equivalent certification will be considered an additional asset.



