Role & responsibilities
- Monitor and analyze security alerts from SIEM, EDR, IDS/IPS, and email security platforms
- Perform threat hunting, IOC analysis, and adversary tracking activities
- Analyze phishing, malware, and suspicious network activities
- Correlate threat intelligence feeds and provide actionable insights to SOC/Vulnerability teams
- Conduct incident investigation, containment, and reporting
- Monitor brand/domain impersonation and external threat activities
- Prepare executive security reports and incident documentation
- Work with tools such as Splunk, CrowdStrike, Microsoft Defender, FireEye, Proofpoint, Palo Alto, and ThreatConnect
Required Skills:
- Experience in SOC Operations and Cyber Threat Intelligence
- Strong knowledge of SIEM, EDR, IDS/IPS, and email security solutions
- Hands-on experience with Splunk, CrowdStrike, Microsoft Defender, FireEye, or similar tools
- Understanding of phishing analysis, IOC management, and threat hunting
- Good analytical, communication, and report-writing skills
Preferred Qualifications:
- 46 years of experience in SOC/Threat Intelligence roles
- Certifications in Cyber Security or Threat Intelligence are a plus