— Design and deploy SIEM/SOAR solutions (Elastic/Splunk/SentinelOne);
— Integrate diverse data sources from cloud and on-prem infrastructure into a central SIEM;
— Set up and maintain threat intelligence feeds and detection rules;
— Lead incident handling and improve response processes;
— Detect, investigate, and respond to security threats and vulnerabilities;
— Design and deploy Antivirus, EDR/XDR solutions;
— Set up and maintain VPN, MFA, SSO solutions;
— Detect, investigate, and respond to security threats and vulnerabilities;
— Collaborate with technical teams to enhance overall security;
— Create reports on incidents, trends, and system performance;
— Recommend and implement security best practices.