Experience with security incident management and network monitoring in medium to large organizations
General Information Security experience CISSP preferred
Strong communication skills and experience working in the enterprise
Strong familiarity with security technologies in general both at the host and network level
Knowledge of Palo Alto Networks products
Working knowledge of Splunk, Splunk Enterprise Security
Scripting experience and experience developing or integrating of security tools using APIs
Experience with Forensic Analysis EnCase or similar is a plus
Responsibilities
The role will lead the day-to-day management of the Global Security Operations team specifically in incident detection and response with the Regional Teams across the Client Group Business Units
The role will lead each of the Business Units in running Security Incident Response Drills and Table Top Exercises
The role will be the main point of escalation for any security detections from Crowdstrike and Vectra
The role is pivotal in coordination management escalation and reporting of security related matters as well as providing evidence for ISO27001 and SOC2 audits
The role is responsible for installing configuring monitoring of EDR and Netksope agents across all of Business Units globally
The role will be managing Vendors represent the Global SOC in QBRs highlight gaps to vendors for improvement
Manage and maintain all Blue Team playbooks and ensure Crowdstrike Fusion SOAR automations are uptodate and operational
The role requires a knowledge in running scripts and workflows eg python powerautomate to run daily operational tasks including health checks threat hunting threat detection
Maintain and ensure that all Security Tools are fully integrated and feeding logs into NextGen SIEM
Perform Threat Hunting using NextGen SIEM able to find specific logs using Crowdstrike Query Language and create Fusion Workflows to detect IOCs notify teams for TTPs and apply automated remediations
Perform daily health checks of all Security Tools ensuring they all are operational