Providing continuous technical monitoring (such as intrusion identification, event correlation and threat containment), detection, correlation, analysis and support involving handling of cyber event such as identifying user security issues;
Performing initial analysis (e.g. analysing and reviewing alerts, eliminating false positives and determining severity of threats) to determine impact of compromise;
Determining the nature, mechanisms and scope of incident by performing event correlation and historical searches to determine the extent of a security compromise;
Performing event correlation across the In-Scope Institutions to identify similar attack pattern and spread of attack;
Handling case management, generating tickets and reports when required, and tracking open tickets until closure;
Generating incident or investigative reports.
Qualifications:
At least TWO (2) years of experience working in a Security Operation Center with security monitoring and escalation of threats responsibilities;
Relevant training on the proposed products, and has obtained professional certification such as GIAC Information Assurance Certified Intrusion Analyst (GCIA), GIAC Information Assurance Certified Incident Handler (GCIH), or equivalent.