Дополнительно
Operate our vulnerability scanner: maintain coverage, manage scan schedules, and keep agents/engines healthy
Run weekly triage of findings — assess severity × exposure, deduplicate results, and assign issues to owning teams
Track remediation against SLAs, follow up with teams, verify fixes, and re-scan to confirm closure
Monitor vulnerability feeds and vendor advisories (GitLab, Ubuntu, network equipment, key dependencies) and flag time-critical patches
Maintain vulnerability metrics: open criticals, finding age, and mean time to patch
Operate our central log pipeline: onboard new log sources, monitor shipper health, and manage retention
Maintain and tune detection rules and alerts (authentication anomalies, firewall changes, privileged actions, exchange-account events)
Triage security alerts, escalate according to playbooks, and participate in the on-call duty rotation
Support incident response: evidence collection, timeline reconstruction, and post-incident follow-up