Take command of critical incidents by managing cross-functional and technical coordination efforts to ensure alignment, timely communication, and effective execution of the incident resolution process.
Advance and mature the proactive response pillar within CSIRT by providing architectural-level expertise in threat hunting, threat intelligence, and detection engineering, ensuring the organization remains ahead of evolving cyber threats.
Lead the development and optimization of detection and response capabilities by collaborating with engineering, intelligence, and operations teams to identify gaps, enhance threat visibility, and implement actionable improvements.
Direct and refine incident response frameworks by creating and maintaining playbooks, operational methodologies, and case management standards that strengthen both reactive and proactive response operations.
Coordinate the generation and sharing of critical insights from incident investigations, threat hunting outcomes, and detection enhancements with internal stakeholders and executive leadership to drive organizational resilience and informed decision-making.
Essential Requirements
10+ years of directly related experience in Information Security Threat Detection and Incident Response.
Experience presenting technical information to executive stakeholders.
Deep technical knowledge of adversarial attack methods, tools, and technologies.
Familiarity with security vulnerabilities, exploits, malware, various types and techniques of cyber-attacks and digital forensics
Strong understanding of the MITRE ATT&CK knowledge base, the Cyber Kill Chain, and the Diamond Model
Desirable Requirements
Experience in development and automation.
Experience setting collection and intelligence requirements in a cyber environment.