1. Security Monitoring & Detection Engineering
● Develop and maintain detection rules, dashboards, alerts, correlation logic, and analytics within:
•
cloud-native SIEM/SOC tools
•
endpoint detection tools (EDR/XDR)
● Build detections and emerging threat patterns.
● Configure, monitor and troubleshoot security infrastructure devices and services such as EDR, DLP or CASB
● Identify opportunities for, and promote automation and new technical solutions and security tools to help mitigate security vulnerabilities and improve efficiency
2. Incident Investigation & Threat Response
● Perform L3 investigation of security alerts, including:
•
anomalous authentication events
•
suspicious network activities
•
API misuse or credential abuse
● Execute containment and remediation actions in collaboration with cybersecurity teams, IT Ops and Engineering teams
● Produce clear incident reports and contribute to RCA and continuous improvement.
● Establishing disaster recovery procedures and conducting breach of security drills.
3. Threat Hunting
● Conduct proactive threat hunts using:
•
anomalous behavior detection
•
historical investigations
•
cloud & API-specific threat vectors
● Identify gaps in security visibility and propose instrumentation improvements.
4. Security Logging & Observability Integration
● Ensure complete and reliable logging coverage across:
•
Cybersecurity tools (EDR, DLP, etc.)
● Work with Observability teams to ensure correlated visibility (Dynatrace + Splunk).
5. Vulnerability & Attack Surface Support
● Support vulnerability management by correlating findings with real activity logs.
● Validate remediation and track exploitation attempts related to EMG systems.
● Assist IT Ops and Engineering teams to prioritize and mitigate vulnerabilities.
6. Cyber Security Controls Validation
● Validate enforcement of cybersecurity standards (E.g., Zero Trust, MFA, encryption, identity governance).
● Test security controls effectiveness through simulations or red-team collaboration.
7. Documentation, Playbooks & Knowledge Sharing
● Maintain SOC runbooks, response playbooks, detection documentation, and forensic procedures.
● Identify and communicate current and emerging security threats
8. Collaboration Across IT & Business
● Work closely with:
•
CISO (governance, escalation, risk alignment)
•
Cybersecurity Architecture Manager
•
Cloud & Production Services
•
Network & Infrastructure Ops
● Ensure consistent communication and coordination during incidents and monitoring activities.