- Monitor and review security logs and alerts using Microsoft Sentinel.
- Help develop and tune detection rules, workbooks, and playbooks.
- Help identify potential threats, anomalies, and indicators of compromise.
- Work with the InfoSec team to escalate and act on actionable alerts.
- Take part in incident handling efforts, helping to identify, contain, investigate, and remediate security incidents.
- Help identify root causes and conduct post-incident reviews.
- Assist in developing detection use cases and contribute to threat hunting activities using Microsoft Sentinel and other tools.
- Document incidents, findings, and remediation actions thoroughly.
Information Security Risk Assessment:
- Assist in conducting comprehensive risk assessments to identify potential security threats and vulnerabilities.
- Review and document risks, recommend mitigations, and track remediation efforts.
- Follow-up with risk owners on risk mitigation.
Supplier Risk Assessment and Coordination:
- Help evaluate third-party vendors and suppliers to ensure they meet our security standards.
- Coordinate with suppliers to gather necessary security information and ensure compliance with our policies.
ISO 27001 Audit Preparation:
- Assist in preparing documentation and evidence for ISO 27001 and other audits.
- Help facilitate internal and external audit processes, ensuring all required information is accurate and complete.
Daily Operations Assistance:
- Aid the Information Security Team in daily operations, tickets and administrative tasks.
- Maintain and update security policies, procedures, and documentation.
Learning & Development:
- Get hands-on exposure to tools like Microsoft Defender, Intune, and Azure Security Center.
- Learn how to perform basic threat intelligence research and enrich alerts with context.
- Access internal training resources and mentorship from experienced InfoSec professionals.