Job Summary:
We are looking for a highly skilled Anti-APT and IncidentResponse Specialist to lead the detection, analysis, and remediation ofsophisticated cyber threats, including Advanced Persistent Threats (APTs). Thecandidate will work closely with threat intelligence, SOC, and forensic teamsto respond to incidents, contain threats, and fortify the environment againstfuture attacks.
Key Responsibilities:
Anti-APT Operations:
Monitor for indicators of APT campaigns using threat intelligence feeds, SIEM, EDR, NBAD, and anomaly detection tools.
Identify and analyze tactics, techniques, and procedures (TTPs) used by threat actors aligned with MITRE ATT&CK.
Leverage threat intelligence to proactively hunt and neutralize stealthy threats.
Incident Response (IR):
Lead and execute all phases of incident response: identification, containment, eradication, recovery, and lessons learned.
Perform forensic analysis on systems and logs to determine the root cause, scope, and impact of security incidents.
Collaborate with IT, SOC, and legal/compliance teams during major incidents and breach investigations.
Create and maintain IR playbooks, response workflows, and escalation procedures.
Detection and Prevention:
Work with SIEM and SOAR teams to improve alert fidelity and develop custom correlation rules.
Coordinate with endpoint, network, and cloud teams to plug gaps and strengthen defenses post-incident.
Assist in configuring anti-APT technologies like sandboxing, deception platforms, and EDR/XDR solutions.
Required Skills and Qualifications: