Responsibilities
- Lead security operations activities, managing and maintaining the organization's security
monitoring and detection capabilities.
- Coordinate and execute incident response strategies, swiftly identifying, containing, and
mitigating cybersecurity incidents.
- Conduct detailed incident investigations to determine root cause, document findings, and
implement proactive measures to enhance detection and response effectiveness.
- Collaborate cross-functionally with IT and business units to facilitate the prompt remediation of
identified vulnerabilities, minimizing operational disruptions.
- Monitor and analyze emerging threat intelligence feeds, integrating insights into proactive security
measures to defend against advanced threats.
- Regularly review, assess, and optimize security controls and incident response protocols.
- Develop and maintain clear documentation, including incident response playbooks, security
reports, and post-incident analyses.
- Provide actionable recommendations based on lessons learned from security events to
continuously enhance security posture.
- Contribute actively to the development and refinement of cybersecurity policies, procedures, and
standards in alignment with regulatory and compliance requirements.
- Collaborate closely with IT and other internal teams to implement integrated and effective cybersecurity practices.
- Create and maintain real-time security monitoring dashboards to provide visibility into organizational cybersecurity health.
- Stay current with cybersecurity trends, threat intelligence, and evolving risks to ensure proactive defense measures.
- Participate in cybersecurity awareness training initiatives, promoting a security-focused culture throughout the organization.
- Serve on an on-call rotation to ensure timely response to cybersecurity incidents outside regular business hours, including nights and weekends.
Basic Qualifications
- Minimum 3 years of professional experience in Security Operations (SecOps) or related
cybersecurity roles.
- Comprehensive understanding of cybersecurity principles, threat intelligence methodologies, and
frameworks (NIST, ISO 27001, MITRE ATT&CK).
- Proven experience in cybersecurity incident response, threat detection, and threat intelligence
analysis.
- Proficiency in configuring and managing advanced security monitoring tools such as SIEM, EDR,
and threat intelligence platforms.
- Exceptional analytical and problem-solving capabilities with a focus on rapid incident
containment and remediation.
- Strong communication and collaboration skills, with fluency in English.
- Relevant certifications (e.g., CISSP, CISM, CEH, CompTIA Security+) strongly preferred.
- Ability and willingness to travel domestically and internationally up to 10%.
Preferred Characteristics
- Bachelor’s or Master's degree in Computer Science, Information Security, or a closely related
discipline.
- Operational Technology (OT) security experience, particularly within a global manufacturing
context.
- Experience responding to sophisticated cyber threats, including nation-state actors.
- Prior United States Security Clearance or equivalent.
- Familiarity with regulatory frameworks and compliance requirements, including SOC 1/2/3, ISO
27001, FedRAMP, SOX, HIPAA, NIST, and others.
- Scripting and automation skills in Python, shell scripting, Ruby, or similar languages.
- Previous experience in corporate IT support or help desk roles is beneficial.