Perform continuous monitoring of security information and event management (SIEM), EDR, and firewall logs to identify potential unauthorised activity.
Conduct initial analysis and triage of security alerts, coordinating with stakeholders to contain and remediate low-to-medium complexity incidents.
Document incident findings and support the development of post-incident reports to improve future detection capabilities.
Stay current on the cyber threat landscape to proactively identify risks relevant to the organization’s specific industry and infrastructure.
Security Engineering & System Hardening
Collaborate with the IT team to implement and audit baseline security configurations for all endpoints.
Assist in the management of Identity and Access Management (IAM) workflows to ensure the principle of least privilege is maintained across all systems.
Execute basic scripting (e.g., PowerShell, Python) to automate routine security checks and administrative tasks.
Qualifications & Skills
Education: Bachelor’s degree in Cybersecurity, Information Technology, or a related field; or equivalent professional experience.
Experience: 1–2 years of experience in a technical IT security role (such as System Administration or Network Support) with a demonstrated focus on security.
Competencies: Strong attention to detail, a disciplined approach to documentation, and the ability to work effectively under pressure during active security incidents.
Technical Proficiency:
Foundational understanding of network protocols (TCP/IP), firewalls, and encryption standards.
Experience with Windows OS, Mac OS and Linux administration.
Ability to interpret log data and identify patterns of malicious behavior.