About the role
- Monitor security events, alerts, and logs across enterprise systems and infrastructure.
- Detect, investigate, and respond to potential security incidents and threats.
- Analyze security alerts from SIEM, EDR, firewall, endpoint, and other security tools.
- Perform initial investigation, triage, and escalation of security incidents.
- Conduct threat analysis to identify suspicious activities, vulnerabilities, and potential attacks.
- Troubleshoot and investigate security-related incidents and anomalies.
- Support incident response activities and follow established security response procedures.
- Use SIEM platforms to correlate logs, identify patterns, and investigate security events.
- Work with SOAR and security automation tools to automate repetitive security monitoring and response activities.
- Document security incidents, investigation findings, and remediation actions.
- Collaborate with Network, Server, System, and IT teams to contain and resolve security incidents.
- Stay updated on emerging cybersecurity threats, attack techniques, and security best practices.
