Threat Detection & Response Senior Specialist
Core
Senior specialist in the Cyber Security Operations Center (CSOC) responsible for real-time security monitoring, incident response, forensics, and threat detection across Novartis' IT ecosystem.
Role type
Senior IC threat detection and response specialist
Builds
Incident response playbooks, automation workflows, and detection logic for enterprise security
Domain
Cybersecurity, IT Operations, Threat Intelligence
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
Incident response, threat detection, security operations workflows, alert triage, escalation management, log analysis, forensic artifact analysis, malware analysis, network packet analysis, host-based analysis, SIEM usage, EDR/XDR usage, identity monitoring, case management
Preferred skills
Python scripting, PowerShell scripting, Bash scripting, malware reverse engineering
Technologies
SIEM, EDR, XDR, email security, case management tools
Responsibilities
Monitor security controls and consoles in real time; conduct initial investigations into security incidents; gather live evidence from endpoints and logs; analyze logs, alerts, and forensic artifacts; develop and maintain response playbooks and documentation; perform quality assurance reviews of investigations; mentor junior staff; recommend new detection logic and tune security controls
Seniority
Senior, hands-on IC