• Security Monitoring & Incident Response: Serve as a front-line SOC analyst responsible for monitoring, triaging, investigating, and responding to alerts across endpoint, network, identity, cloud, and other security platforms. Determine scope, severity, and potential impact; take appropriate initial containment actions and escalate complex or high-impact incidents as needed.
• Threat Analysis & Hunting: Analyze security telemetry, logs, endpoint activity, network traffic, and related data sources to identify anomalous behavior, indicators of compromise, and potential threats. Conduct targeted threat-hunting activities based on emerging threats, intelligence, and observed attacker behavior.
• Detection Engineering: Assist with developing, testing, tuning, and maintaining SIEM detection rules, correlation logic, and alerting capabilities to improve detection coverage, reduce false positives, and address emerging attack techniques.
• Security Tool Administration: Support the configuration, integration, maintenance, and operational effectiveness of technologies including SIEM, EDR, IDS/IPS, and related endpoint and network security controls.
• Vulnerability Management: Assist with vulnerability scanning, analysis, prioritization, and remediation tracking across systems, applications, and infrastructure. Partner with technical teams to validate findings and support timely remediation.
• Threat Intelligence: Monitor relevant threat intelligence, vulnerabilities, attacker tactics, techniques, and procedures (TTPs), and emerging security trends. Apply relevant intelligence to investigations, threat hunting, and detection improvements.
• Documentation & Process Improvement: Develop and maintain incident-response procedures, playbooks, runbooks, investigation guides, and lessons learned. Identify opportunities to improve SOC processes, detection capabilities, and response procedures.
• Security Awareness & Testing: Support enterprise cybersecurity awareness programs, including training, phishing simulations, and other awareness-testing campaigns. Analyze results and help identify opportunities to strengthen employee security awareness.