Activity: CSOC Incident Monitoring, Response and Performance
Responsibilities and Accountabilities:
- Act as the first point of escalation when an event is escalated into a potential threat or incident and provide communication exchange and knowledge transfer with other CSOC teams, internal and external stakeholder.
- Administer CSOC Standard Operating Procedure (SOP), Incident Response Plan (IRP) and review their application to ensure the controls, SOP, and IRP are operating effectively and efficiently.
- Engage and provide management oversight for the identification, triage, and response of events or incidents of apparent security breaches.
- Ensure compliance to SLA, process adherence and process improvisation to achieve operational objectives.
- Collect and maintain data needed to meet security reporting to CSOC Manager.
- Maintain processes and procedures associated with security monitoring and response use cases to address and respond to potential security incidents and promote timely escalation and incident coordination.
- Support the configuration of existing tools and evaluate existing rules, filters, events and use cases to analyze security event data, detect suspicious activity, and alert on potential security incidents.
- Drive collaboration efforts between the CSOC and counterparts to maximize effectiveness of detection efforts and knowledge of the local cyber security landscape.
Operational Planning
Responsibilities and Accountabilities:
- Provide input into the development of the Department’s systems and processes, as well develop, and implement the Section’s procedures, identifying opportunities for the continuous improvement of practices to increase productivity and operational efficiency.
- Monitor, control and report Operational and financial Key Performance Indicators (KPIs) related to the Section, to track performance and recommend corrective or mitigating actions.
- Ensure that all