Act as the primary escalation point for complex security incidents and investigations from L2 analysts.
Led coordinated incident response efforts involving IT, business units, and external partners.
Perform advanced digital forensics, memory analysis, and malware reverse engineering to determine threat capabilities, persistence mechanisms, and impact.
Analyze malicious code to extract indicators, identify vulnerabilities, and recommend detection and mitigation strategies.
Perform advanced threat hunting across multiple data sources to uncover sophisticated, stealthy, and targeted attacks.
Develop and maintain advanced detection rules, analytics models, and playbooks for complex threat scenarios.
Lead post-incident reviews to ensure root causes are identified and corrective measures are implemented.
Integrate and operationalize intelligence from internal and external sources to improve detection and response capabilities.
Provide expert-level guidance to L1 and L2 analysts in technical investigation, threat analysis, and detection tuning.
Collaborate with SOC engineering teams to improve telemetry, log collection, and analytic workflows.
Conduct research on emerging threats, exploit techniques, and security technologies to keep the MSS team's capabilities.
Create and deliver technical briefings, training sessions, and executive-level reports on significant security incidents and threat trends.
Requirements
Graduates from D3, D4, or S1.
Minimum 5 years of working experience with at least 2 years as an L2 Security Analyst.
Expertise in advanced threat detection and response.
Proficiency in malware analysis, reverse engineering (preferred).
Deep knowledge of security architecture, detection engineering, and SIEM tuning.
Familiarity with red/blue/purple team tactics.
Knowledge of regulatory frameworks (e.g., ISO 27001, NIST CSF, MITRE).
Advanced investigative and decision-making skills.
Threat hunting and forensic thinking.
Strategic thinking and long-term planning
Ability to handle high-pressure incidents.
Mentoring and leadership capabilities.
Communication skills
Having one or a few of these certifications would be an advantage: Blue Team Level 1 (BTL1) by Security Blue Team, CIHE, ECIH, CHFI, BTL2, eJPT, eWPT, CEH, eCTHP, CompTIA Cybersecurity Analyst (CySA+), MS-200