Manager(Information Security Section)
CurrentLead the incident response efforts within the Security Operations Center (SOC), conducting real-time analysis of security events and alerts to identify and respond to potential threats. Perform digital forensics investigations to gather evidence, analyze artifacts, and determine the root cause of security incidents and breaches. Utilize forensic tools such as EnCase, FTK, and Volatility to conduct disk imaging, memory analysis, and file system forensics on compromised systems. Utilize SIEM (Security Information and Event Management) tools such as Splunk, ELK to monitor and analyze security events and alerts in real-time. Investigate and triage security incidents to determine their nature, scope, and impact on the organization's systems and data. Conduct in-depth analysis of security logs, network traffic, and endpoint telemetry to identify indicators of compromise (IOCs) and signs of malicious activity. Collaborate with cross-functional teams including IT, network engineering, and legal departments to contain and remediate security incidents, ensuring minimal impact on business operations. Develop and maintain incident response playbooks, standard operating procedures (SOPs), and forensic investigation guidelines to streamline incident handling processes and ensure consistency. Conduct threat hunting activities to proactively search for and identify advanced threats and persistent adversaries within the organization's environment. Provide technical guidance and mentorship to junior analysts and SOC team members on incident response techniques, forensic analysis methodologies, and best practices. Participate in incident response tabletop exercises and simulations to test and validate the effectiveness of incident response plans and procedures. Stay abreast of emerging cybersecurity threats, vulnerabilities, and attack techniques through continuous monitoring of threat intelligence feeds and industry publications.