• Coordinate security monitoring, alert triage and escalation with the shared SOC and relevant technical teams.
• Lead operational response to confirmed security incidents in accordance with approved procedures and authority.
• Collect and preserve technical evidence and maintain incident records, timelines and action tracking.
• Coordinate containment, remediation, recovery and post-incident reviews with stakeholders.
• Support security logging, SIEM integration, use-case tuning and monitoring coverage assessments.
• Track technical security risks and remediation dependencies across infrastructure, network, cloud and applications.
• Provide operational security reporting and support agreed awareness, exercise or readiness activities.
• Escalate policy, compliance and risk-acceptance decisions to the authorised Entity function.