Report to Director to facilitate all phases in the incident response lifecycleBe involved in various incident prevention projects to improve Security postureUnderstand different regulatory and compliance requirements like critical time to report, escalation flows, etc.Take part in self-assessment exercises like Tabletop Exercises, Attack Simulations, Red/Purple Team exercises to make sure the incident response process is working smoothlyDevelop incident response runbooks, playbooks and SOPs with reference to different regulatory requirementsEvaluate the incident response readiness of different layers - people, process, technologyRespond to the cyber security incidents escalated from various channels including the 24/7 SOC team.Respond to cyber security incidents in compliance with the local authority / regulatory requirements.Assess the risk, impact and scope of the identified security threatsPerform deep-dive incident analysis of various data sources by analysing and investigating security related logs against medium-term threats and IOCsCommunicate with the stakeholders and provide guidance, recommendations to contain and eradicate the security incidentParticipate in root cause analysis using forensic and other custom tools to identify any sources of compromise and/or malicious activities taking place.Document and present investigative findings for high profile events and other incidents of interest.Provide lessons learnt meeting to the stakeholdersLead and keep track on the follow-up activitiesDocument the incident in the case management system and provide incident reportsAlways ready to jump in, in the event of security incidents.