- Monitor security alerts from tools like SIEM, MDR, and IDS/IPS to analyze potential threats.
- Triage, categorize, and escalate security incidents.
- Assist in incident response, including investigation and containment of threats.
- Perform initial forensic analysis on logs and endpoint events.
- Maintain up-to-date documentation on security events, playbooks, and escalation procedures.
- Collaborate with team members to enhance threat detection and response capabilities.
- Work with clients to remediate issues like business email compromise and malware.
- Support IT teams in applying security policies and best practices.
- Assist in vulnerability management and patching efforts.
- Continuously improve processes by researching new threats and vulnerabilities.