12+ years of experience in Cybersecurity / Information Security
Strong experience with Security Operations / Cybersecurity Operations
Incident Detection, Investigation, Response, and Remediation
SIEM monitoring and security event analysis
Splunk, Microsoft Sentinel, or similar SIEM platforms
EDR/XDR technologies and endpoint security
Vulnerability Management and Risk Assessment
Security Incident Response and Threat Analysis
IAM / Access Management, authentication, authorization, and privileged access
Network Security concepts: TCP/IP, DNS, VPN, Firewalls, IDS/IPS
Security monitoring, alert triage, and escalation
Threat Intelligence and Threat Hunting
Security vulnerability scanning tools such as Tenable/Nessus, Qualys, or Rapid7
Experience with Microsoft Active Directory / Azure AD (Entra ID)
Knowledge of cloud security, preferably AWS and/or Azure
Strong understanding of NIST, CIS, ISO 27001, and security best practices
Experience with security policies, procedures, controls, and compliance
Strong troubleshooting and analytical skills
Excellent communication and documentation skills
Monitor and investigate cybersecurity alerts and incidents.
Perform security event analysis and determine appropriate escalation.
Lead incident response activities from identification through remediation.
Analyze SIEM, EDR, firewall, network, and endpoint security data.
Identify indicators of compromise and potential security threats.
Support vulnerability assessment and remediation activities.
Work with infrastructure and application teams to resolve security issues.
Perform threat hunting and proactively identify suspicious activity.
Support IAM, access reviews, privileged access, and authentication controls.
Participate in security risk assessments and compliance activities.
Develop and maintain security documentation, procedures, and incident reports.
Assist with security audits and control assessments.
Recommend improvements to security monitoring, detection, and response capabilities.