Key Responsibilities:
- Incident Response: Lead and manage cyber incident investigations, ensuring timely and effective resolution.
- Automation Development: Utilize Phantom and Python to develop and maintain automated response playbooks and scripts.
- Threat Analysis: Analyze and interpret security events and logs to identify potential threats and vulnerabilities.
- Collaboration: Work closely with other cybersecurity teams to integrate automated response solutions into existing workflows.
- Documentation: Maintain detailed documentation of incident response processes, playbooks, and automation scripts.
- Continuous Improvement: Stay updated with the latest cybersecurity trends and technologies to continuously improve response strategies.
- Education: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Experience: Minimum of 3 years of experience in cybersecurity, with a focus on incident response and automation.
- Technical Skills:
- Proficiency in Python programming.
- Experience with Phantom or similar Security Orchestration, Automation, and Response (SOAR) platforms.
- Strong understanding of cybersecurity principles and best practices.
- Familiarity with SIEM tools and threat intelligence platforms.
- Certifications such as CISSP, CEH, or GIAC.
- Experience with other programming languages and automation tools.
- Knowledge of cloud security and related technologies