Threat Detection & Response:
- Monitor security tools (e.g., CrowdStrike, Uptycs) for potential threats, malware, and other malicious activities.
- Investigate security incidents and respond to detected threats using endpoint detection and response (EDR) tools such as CrowdStrike.
- Collaborate with incident response teams to mitigate threats and vulnerabilities promptly
- Participation in on-call rotation
Cloud Security:
- Manage and monitor cloud infrastructure security in AWS and Azure environments.
- Implement and maintain security controls across cloud platforms, ensuring compliance with organizational policies.
- Monitor cloud environments for anomalies, misconfigurations, and threats
Email Security:
- Manage and optimize email security systems, specifically Proofpoint, to detect and block phishing, spam, and email-based threats.
- Respond to email security alerts and perform in-depth investigations on suspicious email / user activities.
Vulnerability Management & Scanning:
- Perform vulnerability scanning using appropriate tools, identify security vulnerabilities in systems, and assist in remediation efforts.
- Track and report on vulnerability management processes and ensure that vulnerabilities are mitigated or patched according to the organization’s security policies.
- Conduct regular penetration testing to assess the security of applications and networks.
Security Monitoring & Analysis:
- Use SIEM (Security Information and Event Management) systems to analyze security events, logs, and alerts.
- Correlating threat intelligence feeds internal data to detect advanced threats.
- Perform regular analysis and reporting on security incidents, including root cause analysis.
- Build actionable runbooks, dashboards, secure integrations across multiple tools
Compliance & Risk Management:
- Ensure compliance with industry standards and frameworks such as ISO 27001, NIST, SOC 2, and other applicable regulations.
- Assist in audits and ensure that security policies and procedures are followed.
- Conduct risk assessments to evaluate the organization’s exposure to cybersecurity risks.
- Engage in Third Party Risk management, Supply Chain Attacks and Risks
Security Best Practices & Training:
- Assist in developing and maintaining security policies, procedures, and best practices.
- Provide security awareness training to employees, focusing on phishing, malware detection, and cloud security practices.
Security Automation Tools-Stack:
- ProofPoint DLP
- CrowdStrike XDR / NGSIEM
- Uptycs CNAPP / XDR
- Obsidian Security SSPM
- Nord Security / Dark Web Threat Intelligencer
- Cloudflare WAF
- Claude Code / GitHub-Copilot
- MCP
- Visual Studio Code