Responsibilities :
Lead advanced investigation and response for security incidents identified through EDR, SIEM, SOAR, and Threat Intelligence platforms.
Perform in-depth endpoint analysis to detect malware, persistence mechanisms, privilege escalation, lateral movement, and other advanced threats.
Conduct malware analysis and reversing to identify Indicators of Compromise (IOCs), attack techniques, and remediation actions.
Drive incident response activities including containment, eradication, recovery, root cause analysis, and post-incident reviews.
Perform proactive threat hunting across enterprise endpoints leveraging behavioral analytics and threat intelligence.
Develop, tune, and optimize EDR detections, response playbooks, and automated containment workflows.
Collaborate with SOC, Detection Engineering, Threat Intelligence, and Infrastructure teams to strengthen endpoint security posture.
Document investigations, lessons learned, and recommendations to enhance detection and response capabilities.
Stay current with emerging threats, ransomware trends, attack techniques, and advancements in EDR technologies.