Posted 3
views
Responsibilities * Monitor systems for abnormal activity * Analyze alerts, distinguish threats from false positives, categorize incidents by risk * Lead incident response: containment, eradication, recovery, post-incident analysis, documenting steps * Optimize detection capabilities: refine alert thresholds, tune SIEM rules, integrate new data sources, reduce false positives * Compile weekly/monthly reports on incident trends, threat activity, and security posture for internal stakeholders * Ac…