Provide tier two operational support, leading team efforts in resolution of incidents and outages for information security technology and its dependencies on Public and Private Cloud computing environments, shared platforms, and operating systems for more than three of the following technologies:
Ensuring team's adherence to SOPs, training and performance monitoring for team members, and continuous process improvement for efficiency, including automation, wherever applicable and conduct recurring assessments of all the key SOC workflows to highlight process deficiencies as well as improvement opportunities for staff.
Malware Analysis
SIEM (Splunk)
Software-defined (Cloud) Network Security
Endpoint Security Protection
Data Loss Prevention
Partner with other technology teams in handling and responding to internal customer issues, conducting problem analysis and providing solutions for service level improvements, and ensuring timely remediation of security issues in accordance with corporate policies and standards
Perform Root Cause Analysis (RCA) on applicable technology
Validate quality of dashboards and alerts and suggest updates to reflect new threats and changes in the monitored environment
Support the Security Operations team in its efforts on various technology projects and operational initiatives
Work as a part of a team to ensure that Guardian customers' data, technology platforms, and infrastructure are available and safeguarded from cyber threats
Follow ITIL practices regarding incident, problem, and change management
Stay up to date with emerging cyber threats, industry best practices, and applicable regulatory requirements