About the Role
Trigyn has a contractual opportunity for IT Security Cloud Engineer. This position is Remote.
Key Tasks defined by Global CSIRT are
? Incident Management, including optimizing current detection solutions (Microsoft Defender for Endpoint, Rapid7 Threat Intelligence Platform, Microsoft Sentinel, Third-party Security Incident escalation)
? Vulnerability Management Tracking (review vulnerabilities in real time), follow up with relevant stakeholders about fixing, patching or remediation as well as creation of reports.
? Internal support with relevant project initiatives related to cybersecurity tools (acquisition or improvement)
These activities are critical for the Global CSIRT since incident management and project initiatives can consume most of the working hours of current staff assigned to the group.
Currently, global CSIRT’s third-party security provider is limited to perform specific alert triage analysis and engage with a set of scenarios, which is another advantage of incorporating this profile to strengthen current resource constraints the team is experiencing.
Activities delivered by the CSIRT team categorized as BAU
? Alert review out of the scope of monitoring services (SIEM, Rapid7, Purview)
? Cybersecurity Forum alerts and incidents
? Incidents escalated by e-mail or fresh service
? Incident and Ticket creation on Fresh Service
? Incident Response 24x7
? IOM staff communication (End user, Legal Team, Social Media Team, Infrastructure Team, Office 365 team, infosec unit, Regional Officers)
? Global CSIRT website maintenance
? Internal Report Creation
? Internal log analysis (audit logs, AD logs, web proxy logs)
? Dashboard creation (sentinel)
? Tool management, integration and optimization (SIEM, Rapid7, Purview, Microsoft Suite)
? Information collection and maintenance (endpoint inventory, application inventory)
? Project initiatives and collaboration (DLP, AI, Purview, Application development)
? Audit support (compliance audits, beneficiary requirements, internal infrastructure requirements)
? Internal Security Policy and Control reviews (NIST and CIS)
? Vulnerability assessment for local offices and follow up
? Tabletops and training for all regions and staff (general users, local ICTs, Senior Management)
The following capabilities are required from the Cybersecurity Consultant Profile:
1. Able to collaborate and accurately articulate cybersecurity scenarios to technical and non-technical staff
2. Microsoft Sentinel mid-high level experience (dashboard creation, source management, log analysis)
3. Microsoft Defender for Vulnerability Management experience (Vulnerability hunting, dashboard creation, remediation follow-ups)
4. PowerBI integration and report creation
5. AI knowledge, specifically using Copilot for Security
6. Demonstrated CSIRT experience including handling of incidents, playbook creation and team management.
For Immediate Response, please send your Resume to Global-Recruitment@Trigyn.com
TRIGYN TECHNOLOGIES is a multinational IT services company with resources deployed in 28 countries. TRIGYN is an ISO 9001:2015, ISO 27001:2022 (ISMS) and CMMI Level 5 certified company. TRIGYN has offices in the United States, Canada, Switzerland and India.