Understands the phases of security incident response and the Cyber Kill Chain
*RESPONSIBILITIES*
Analysis and investigation of alerts arising from Security Information and Event Management tools
General day to day maintenance of the SIEM technology stack, including refinement of rules, alerts and reports arising from both traditional SIEM and Next Gen User Behavior Analytics (UBA) tools
Full ownership of the Security Incident management process, including customer notification, severity-based prioritization, investigation, regular customer updates, identification of remedial actions, reporting and closure
Using SIEM and UBA tools to track and analyze events and abnormal user behaviors in order to identify and understand potential breaches, malware and other malicious activities
Using Threat Intelligence Services to identify both known and potential new threats and develop new mitigations
Working with customer security teams to detect, contain and eradicate threats
Good understanding of wider IT and security related toolsets such as Firewalls, endpoint and Active Directory
Understanding of security assessment processes and industry compliance standards (eg ISO27001, PCI) advantageous but not essential