JD:** This position is for the persons who are residing in the Canada**Experience: 5+ Years of experience
Primary focus: Security monitoring, threat detection, investigation, response, and operational automation.
What this person should be able to do Monitor security events and support incident response.
Develop and improve threat detection and investigation workflows.
Work with SIEM and SOAR platforms.
Develop playbooks and automation for repeatable response activities.
Support endpoint and cloud security operations.
Key technical / capability areas SIEM and SOAR platforms.
Threat detection and investigation.
Incident response workflows.
Playbook development and automation.
Endpoint and cloud security operations.
What robust candidates will demonstrate Demonstrates analytical depth during investigations.
Can tune detection and response processes to reduce noise and improve speed.
Looks for opportunities to automate repeatable operational work.