You will monitor security tools including Security Information and Event Management (SIEM) systems to detect suspicious activity.
Analyse alerts and logs to determine if an event is a genuine security incident or a false positive. You will need to be methodical and follow established procedures to classify and prioritise incidents.
For confirmed incidents youll perform initial containment actions such as isolating affected systems and escalate the incident to a Level 2 or 3 analyst for deeper investigation.
Create detailed tickets and reports for all detected incidents documenting your findings and the steps you have taken as this is crucial for tracking incidents and for future analysis.
Also to assist in the maintenance and optimisation of security tools ensuring they are working correctly and effectively.Required Experience:
Senior IC
Certes IT Service Solutions provides security solutions for high performance networks for government agencies and federal organizations.