Cyber Security Operations Leader
CurrentDeploy and manage Endpoint Threat Protection and Detection (EDR). Detecting suspicious and malicious activities, containing and propagating block action using file hash across laptops. Network Detection and Response- baseline ingress and egress traffic, identify new and suspicious traffic to either validate or contain for further investigation.Perimeter security using firewall and URL proxy to categorize the traffic type - unknown web sessions, tracking outbound traffic destination to known and unknown domains and performing traffic analysis between source and destination to detect malicious activity.Data Loss Prevention - Validate critical data movements for classified crown jewels. Manage security incident processes for data movement outside of the organization. Report and escalate unauthorized data movement to legal and HR for policy enforcement.Security Operations Center Management- Perform threat analysis on new TTP on new and emerging threats, visibility coverage across the IT and OT landscapes for threat detection and prevention.Operational Technology Management- Protect and manage Inventory or vulnerable assets exposed to exploits on the OT landscape. Detective controls using OT firewall and NDR solutions to detect, contain and report threats emerging from the OT space.Vulnerability Management - Perform weekly scans and report vulnerabilities for the IT assets, track for zero-day exploits and attack methods. Track and enforce remediation measures to reduce the exposure time.