Design, implement, configure, and administer enterprise security solutions.
Monitor security alerts and events from SIEM, EDR/XDR, firewall, IDS/IPS, email security, cloud security, IAM, and network security tools.
Manage and optimize CrowdStrike Falcon for endpoint protection, EDR, threat hunting, detection, and incident response.
Implement and manage Zscaler security solutions, including ZIA, ZPA, secure web access, and Zero Trust capabilities.
Secure and monitor AWS environments using services such as IAM, GuardDuty, Security Hub, CloudTrail, Config, KMS, VPC, WAF, and related security controls.
Monitor security alerts, investigate incidents, perform root-cause analysis, and coordinate remediation.
Investigate alerts and determine whether they are false positives, suspicious activities, or confirmed security incidents.
Develop and tune security policies, detection rules, alerts, and security controls.
Perform threat hunting and analyze endpoint, network, cloud, and security telemetry.
Implement security best practices for AWS workloads, applications, identities, and infrastructure.
Support vulnerability management, security assessments, and remediation activities.
Integrate security platforms with SIEM/SOAR and other enterprise security tools.
Participate in incident response, containment, eradication, and recovery activities.
Automate security operations and repetitive tasks using scripting or APIs where appropriate.
Maintain security documentation, architecture diagrams, operational procedures, and compliance evidence.
Collaborate with infrastructure, network, cloud, DevOps, and application teams.