Security Operations & Incident Response
• Lead end-to-end investigation and response of complex security incidents.
• Act as L3 escalation point for SOC analysts and MSSP.
• Coordinate across Security, Engineering, IT, Cloud, Legal, and Compliance during
• Make clear, risk-based decisions under pressure with strong documentation.
• Maintain playbooks, runbooks, and incident workflows.
• Drive post-incident reviews and ensure improvements are implemented and follow-ups
• Support incident metrics (MTTD, MTTR, recurrence, etc.)
SOC Tooling & Platform Operations
• Operate and improve SIEM, EDR, email security, case management, and vulnerability
• Monitor health, coverage, data quality, and integrations.
• Troubleshoot ingestion, parsing, API, and configuration issues.
• Build and maintain integrations between security tools and internal systems.
• Manage upgrades, changes, access reviews, and documentation.
• Apply engineering practices (version control, testing, peer review, rollback).
• Reduce operational toil through automation and simplification.
• Analyse and prioritise vulnerabilities based on risk and exploitability.
• Work with Engineering and IT to drive remediation.
• Track fixes, validate resolution, and escalate high-risk issues.
• Improve vulnerability workflows and automation.
• Identify recurring issues and recommend preventative controls.
• Build, test, and maintain detection rules, queries, and correlation logic.
• Manage full detection lifecycle (build → test → tune → measure → retire).
• Use version control and detection-as-code where possible.
• Reduce false positives and improve detection quality and coverage.
• Map detections to threat behaviours (e.g. MITRE ATT&CK).
• Validate detections through testing, incidents, and simulations.
Log & Telemetry Management
• Onboard and maintain log sources across cloud, identity, endpoint, network, and SaaS.
• Ensure logs are complete, reliable, and usable for detection and investigation.
• Troubleshoot ingestion, parsing, schema, and data quality issues.
• Build validation and monitoring for telemetry pipelines.
• Offboard unused sources safely with documented impact.
• Improve telemetry coverage by working with engineering teams.
• Monitor threats, vulnerabilities, and attacker techniques.
• Translate intelligence into detections, investigations, and remediation actions.
• Assess relevance to Teya’s environment and risk profile.
• Share actionable insights with relevant teams.
• Improve security posture using trends and intelligence.
• Gather and utilize intelligence for Shadow AI use-cases.
Cross-Functional Delivery
• Partner with Engineering and Platform teams on security requirements.
• Manage security work in Jira with clear scope and ownership.
• Support security projects (tooling, integrations, telemetry, controls).
• Contribute to technical design discussions.
• Produce clear technical documentation and workflows.
• Communicate effectively with technical and non-technical stakeholders.
• Automate SOC and security operations workflows.
• Build scripts, integrations, and event-driven automations using APIs and cloud services.
• Apply secure engineering practices (testing, logging, secrets management, error
• Use version control and peer review for automation and detection content.
• Monitor and improve automation reliability.
• Explore AI/automation opportunities to reduce manual effort.
• Define and track operational and security metrics.