صاحب العمل نشط
1. Detect, classify, and report incidents to either escalate to the triage team or close the event to ensure the root cause of the incident.
2. Identify security risks and communicate escalations throughout the incidents per the Security Operations Center (SOC) processes.
3. Communicate directly with data asset owners and business response plan owners during high severity incidents to maintain the integrity of the Investigation.
4. Perform analysis of log files to investigate the events to identify the root cause of the incident.
5. Recommend tuning Security Information & Event Management (SIEM) filters and correlation rules to continuously improve monitoring and detection.
6. Create monitoring dashboards to ensure real time awareness of security.
دوام كامل