Make an impactThe Cyber Security Incident Responder is responsible for monitoring, investigating, triaging, and responding to cybersecurity incidents across the enterprise within established operating procedures. The role supports the Security Operations Center (SOC) by analyzing security alerts, conducting investigations, coordinating containment and remediation activities, and continuously improving detection capabilities. The successful candidate will work closely with global IT and security teams to reduce cyber risk and strengthen the organization's security posture.
- Perform daily security monitoring, incident triage, investigation, containment, and response activities in accordance with established SOC procedures and service level agreements (SLAs).
- Monitor, investigate, and respond to security alerts using Microsoft Sentinel, Microsoft Defender XDR, and other security technologies.
- Ability to identify issues, compromised computers using logs, and related computer-centric evidence sources
- Document investigations, findings, and remediation actions accurately within case management systems.
- Contribute to security use-case tuning and continuous detection improvement. Support automation initiatives through SOAR playbooks and workflow optimization.
- Demonstrate ability to perform event analysis and tools utilization (identification, response, escalation)
- Exercise attention to detail and due care in regards to work-related communication and documentation.
- Exhibit willingness to learn, a desire to collaborate with others, and the drive to take on additional responsibilities when called upon.
- Pursue job-related growth and knowledge via higher education, certification, and training.
- Maintain awareness of changing processes, procedures, and standards critical to job performance.
What you need to succeed- IT Experience Or Bachelor's degree in Computer Science, Information Security, Information Technology, or a related field, or equivalent practical experience.
- Knowledge of windows OS / General IT (Debugging and IT Problem solving)
- Knowledge of phishing, malware, ransomware, account compromise, and insider-threat investigations is a plus
- Basic understanding of SOAR technology is a plus
- Experience working in a 24x7 SOC or shift-based operational environment is an advantage.
- Understanding of common network services (Web, mail, DNS, authentication) is a plus
- Previous hands-on experience in the field of IT security (Threat prevention, SIEM, Endpoint protection) is a plus
- Experience with scripting or automation using PowerShell, Python, or similar technologies is an advantage.