- Monitor and respond to advanced threats and evolving attack vectors across multiple environments.
- Perform in-depth investigation and triage of security alerts to determine root cause, impact, and relevance.
- Correlate alerts and telemetry from SIEM and log sources like EDR, IPS, Firewall and threat intelligence platforms to identify real threats.
- Handle detections targeting cloud infrastructure, services, and applications.
- Provide recommendations for containment, mitigation, and recovery to client or internal response teams.
- Contribute to the development and fine-tuning of detection rules, analytics, and use cases to enhance threat visibility.
- Collaborate with Threat Intelligence, SOAR, and Engineering teams for enrichment and analysis.
- Document investigations and findings in accordance with SOC SOPs.
- Develop and maintain SOPs, playbooks, and runbooks.
- Mentor and guide junior analysts to ensure operational quality and SLA adherence.
Scripting