Own day-to-day security operations, monitoring, alert analysis, and incident response to ensure the security, stability, and compliance of company systems.
Operate and maintain core security platforms (NDR, WAF, firewalls, EDR, SIEM, bastion hosts, etc.), continuously tuning detection rules and policies.
Perform initial triage, classification, root-cause analysis, and remediation of security incidents; produce incident analysis reports.
Conduct regular security assessments and penetration testing of web systems, mobile apps, and firmware to identify potential vulnerabilities.
Track emerging threat intelligence, 0-day vulnerabilities, and offensive/defensive techniques; assess business impact.
Support enterprise security planning, compliance assessments (e.g., MLPS), and broader security program initiatives.
Support security awareness initiatives such as phishing simulations and training.
Requirements
Basic Requirements
Bachelor's degree or above in Computer Science, Information Security, Data Science, or a related field.
3+ years of experience in security operations or penetration testing.
Strong sense of ownership and readiness for on-call / incident response duties.