- Operation and tuning of security monitoring tools including Endpoint Detection & Response (EDR), network monitoring, email security, Data Loss Prevention (DLP), Security Information and Event Management (SIEM), security automation tools, and others as needed
- Identification and analysis of anomalous activity in customer technology environments
- Triage of event data to identity potential indicators of compromise
- Escalation of potentially malicious activity to engage incident responders where necessary
- Participation in incident investigation, containment, remediation, and recovery activities where necessary
- Developing and maintaining customer relationships to facilitate delivery of MDR services
- Developing and delivering reports on identified activity to customer stakeholders as needed