Advanced Information Security Engineer
CurrentConducting trade-offs, prototyping, designing, and implementing new/existing IT and network security solutions to safeguard EUMETSAT’s assets, data, and personnel against loss of integrity, availability, and confidentiality. • Managing & administrating infrastructure security systems & solutions including Defender XDR, TrendMicro XDR, Cylance EPP, Splunk SIEM, SyslogNG, Rapid7 InsightVM, Paloalto NG Firewalls, Azure/AWS Cloud Security & Email Security.• Overseeing the full… Show more Conducting trade-offs, prototyping, designing, and implementing new/existing IT and network security solutions to safeguard EUMETSAT’s assets, data, and personnel against loss of integrity, availability, and confidentiality. • Managing & administrating infrastructure security systems & solutions including Defender XDR, TrendMicro XDR, Cylance EPP, Splunk SIEM, SyslogNG, Rapid7 InsightVM, Paloalto NG Firewalls, Azure/AWS Cloud Security & Email Security.• Overseeing the full lifecycle of activities in IT systems & applications vulnerability management, which includes conducting vulnerability assessments, ensuring timely patching, and hardening of infrastructure in operational environments. • Investigating security incidents by analyzing real-time and historical event data generated by various sources (such as logs of servers, firewalls, IPS/IDSs, Endpoint Protection solutions, Azure logs, etc.) using SIEM/SOC and other analysis tools.• Playing a pivotal role in incident response and 24/7 Computer Emergency Response Team (CERT) activities, contribute to the organization's cybersecurity incident resolution capabilities in collaboration with third-party SOC service providers.• Leading the strategic development and continuous maintenance of content, including Rules, Reports, Dashboards, and Filters for the SIEM & SOC.• Applying malware analysis techniques, tools, and processes to strengthen the defense against potential cyber threats. Utilizing threat hunting techniques and gathering threat intelligence to proactively identify and mitigate security risks.• Conducting forensic analysis, asset identification, management, and status reporting to enhance overall cybersecurity resilience. Show less