- Performs as the Senior Technical SME in the area of Cyber Security.
- Incorporates threat intelligence into countermeasures to detect and prevent intrusions and malware infestation.
- Identifies threat actor tactics, techniques and procedures and based on indicators develops custom signatures and blocks.
- Interacts with the personnel for incident response, recovery, and prevention.
- Interacts with the personnel to maximize cyber threat prevention measures, enhance audit and logging standards, and enforce and monitor effective cyber security policies and configurations and security event management within the logging and SIEM infrastructure.
- Implements the core Security Intelligence Center (SIC) concepts (SOC vs. SIC, Cyber Kill Chain, APT).
- Examines different methods of policy creation, implements a security policy, and creates a policy document.
- Studies the detection and prevention of intrusion and attacks.
- Navigates the command line using specific expressions to manipulate data.
- Handles and organizes disparate data about detections, attacks, and attackers.
- Discovers techniques and vetting of new intelligence.
- Builds better actionable intelligence from data.
- Performs related work as assigned.
|