Measure and track the effectiveness of our assurance activities, from assessment coverage and finding severity trends to remediation rates and compliance posture
Wear multiple hats to keep our systems honest. You may be leading a penetration test, conducting a secure architecture review, facilitating a threat modelling exercise, or advising on a governance/risk/compliance matter
Build a culture of accountability and continuous improvement with the people you work with
...
Design, implement, and support cybersecurity solutions across cloud and on-prem environments (SIEM/SOAR, endpoint, cloud security, Zero Trust, vulnerability management)
Perform installation, configuration, and administration of security platforms in cloud platforms (AWS, Azure, Google Cloud) and on-premise environments
Integrate security tools with log sources, identity systems, and monitoring platforms across hybrid cloud environments
...
Create evaluation frameworks for forensic AI workflows, including golden cases, regression tests, grounding checks, hallucination/failure analysis, precision/recall measurement, and investigator feedback loops.
Engineer data workflows across platform audit logs, identity/cloud logs, endpoint/server telemetry, network logs, DLP, and other investigation data sources.
Partner with forensic investigators to turn ambiguous investigative questions into reproducible workflows, reusable query packs, dashboards, agent tools, and defensible technical outputs.
...
Incident Remediation: Take ownership of security alerts and perform active, hands-on remediation tasks (rather than just routing notifications to external desktop or system engineers).
Vulnerability & Audit Management: Execute daily vulnerability assessments, run security scans, handle vulnerabilities, and collaborate/coordinate with third parties to conduct security scans and audits.
Log Analysis & Infrastructure Monitoring: Utilize SIEM and log analysis platforms (such as RSA NetWitness, Splunk, or Elastic Search) to filter, analyze, and investigate security event data across network devices, firewalls, routers, and operating systems.
...
Demonstrated ability to build and improve security operations capabilities, manage external providers, develop team members and influence remediation across functions outside your direct reporting line.
Strong hands-on grounding in the Microsoft security ecosystem, including Sentinel, Defender XDR, Entra ID and Azure, together with experience supporting major incident response, detection strategy and vulnerability management.