Lead day-to-day SOC operations including alert triage, incident queue management, analyst workload balancing, quality review, escalation, and reporting to ensure consistent and high-quality cyber defense outcomes.
Develop, maintain, and continuously improve SOC processes, runbooks, incident response playbooks, escalation matrices, and evidence handling practices that strengthen the organization's detection and response capabilities.
Drive proactive threat hunting using Microsoft Defender XDR, Microsoft Sentinel, Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM), identity logs, endpoint telemetry, network logs, email security telemetry, and cloud activity logs.
...
Lead day-to-day SOC operations including alert triage, incident queue management, analyst workload balancing, quality review, escalation, and reporting to ensure consistent and high-quality cyber defense outcomes.
Develop, maintain, and continuously improve SOC processes, runbooks, incident response playbooks, escalation matrices, and evidence handling practices that strengthen the organization's detection and response capabilities.
Drive proactive threat hunting using Microsoft Defender XDR, Microsoft Sentinel, Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM), identity logs, endpoint telemetry, network logs, email security telemetry, and cloud activity logs.
...
Coordinate and manage application penetration testing activities including scoping, scheduling, evidence collection, vendor coordination, report review, retest tracking, and closure validation to ensure testing outcomes are thorough and actionable.
Conduct or support technical security assessments for web, Application Programming Interface (API), mobile, cloud-hosted, and enterprise applications using manual testing and automated tools, delivering findings that drive meaningful risk reduction.
Own application vulnerability tracking from discovery through to remediation, ensuring findings are categorized by severity, affected application, owner, risk, due date, and closure status to maintain full visibility and accountability.
...
Coordinate and manage application penetration testing activities including scoping, scheduling, evidence collection, vendor coordination, report review, retest tracking, and closure validation to ensure testing outcomes are thorough and actionable.
Conduct or support technical security assessments for web, Application Programming Interface (API), mobile, cloud-hosted, and enterprise applications using manual testing and automated tools, delivering findings that drive meaningful risk reduction.
Own application vulnerability tracking from discovery through to remediation, ensuring findings are categorized by severity, affected application, owner, risk, due date, and closure status to maintain full visibility and accountability.
...