● 3+ years of experience in SIEM(Devo,Splunk, etc) administration roles is a must.
● Led and managed numerous complex security incidents, including ransomware attacks, data breaches, and advanced persistent threats (APTs).
● Experience with scripting languaes(Phyton, bash, etc.)
● Developed and implemented security risks playbooks.
● Analyzed threat intelligence to proactively identify and mitigate potential threats.
● Provide recommendations to improve incident response efficiency looking risks patterns.
● Security Orchestration, Automation and Response implementation and management of SOAR technologies.