· Manage the security event monitoring and incident response ticket queues and triage as appropriate to meet the established service level agreements
· Promptly transfer cybersecurity tickets to the client or internal point of contact
· Clearly convey indicators of compromise, isolation, and remediation steps
· Analyze and interpret system, security, and application logs in order to diagnose faults, spot abnormal behavior, and rule out false positives
· Effectively utilize End Detection and Response tools to investigate alerts, anomalies, and build accurate timelines related to possible compromise
· Follow established procedures to investigate, escalate, contain, or eradicate malicious activity
· Develop and deliver written and oral reports to clients, teammates, and management to aggregate and communicate security information and metrics
· Provide input and recommendations to improve internal processes and procedures related to SOC duties and responsibilities
· Participate in threat-hunting activities and other special projects as required
· Understand and follow, our set of standards and processes that produce a predictable result for the client. You must be aware of and maintain our standards.
Additional Responsibilities:
· Maintain accurate and real-time timesheets, record complete and accurate notes of troubleshooting and communication with clients
· Receive mentoring and feedback from peers and others
· Where appropriate, escalate complicated issues to a more senior resource or other appropriate teams
· Review Tickets with Manager
· Actively Participate in Team Huddles, L10 Meetings, One on One Meetings, and any other Team Meetings
· Create and update documentation when changes occur, or when discoveries are made
· Attend monthly training & team meetings as required
· Additional duties as required