Incident Response and DFIR Lead
- Рівень:
- lead
- Джерело:
- djinni.co
Що робити
- Lead incident response, containment and forensic coordination for confirmed security incidents.
- Act as Incident Commander for major security incidents within the defined authority model.
- Assign incident roles and maintain clear ownership of investigation, containment and recovery actions.
- Maintain incident timelines, evidence logs, decision logs and action tracking.
- Coordinate investigation across endpoints, servers, identities, cloud platforms, SaaS environments and relevant network telemetry.
Що очікуємо
- Strong hands-on knowledge of the incident response lifecycle: investigation, containment, eradication, recovery and lessons learned.
- Experience leading complex security incidents and coordinating multiple technical teams during active response.
- Practical experience investigating endpoint, identity, server, cloud or network compromise using EDR/XDR, SIEM and relevant audit logs.
- Ability to reconstruct attacker activity, including initial access, credential abuse, persistence, privilege escalation, lateral movement, data access and exfiltration.
- Working knowledge of digital forensics, evidence preservation, forensic timelines and chain-of-custody principles.
Схожі вакансії
З блогу Trackr
Усі статті →Знайдено через trackr.help/jobs · Канал: @trackrhelp · Бот для персональних сповіщень: @trackrhelpBot


