Key Responsibilities: Monitor, triage, and investigate security alerts and incidents.
- Perform threat enrichment, correlation, and root cause analysis.
- Execute incident response activities, including approved containment actions.
- Escalate high-severity incidents and coordinate with customer stakeholders.
- Support security monitoring across SIEM, EDR, cloud, and SOAR platforms.
- Document investigations, findings, and remediation recommendations.
- Participate in governance reviews and operational reporting.
Required Skills
- Experience in SOC operations, threat detection, and incident response.
- Hands-on experience with one or more SIEM platforms (Splunk, Microsoft Sentinel, etc.).
- Knowledge of EDR tools such as CrowdStrike, Microsoft Defender, or Tanium.
- Familiarity with SOAR platforms and automated response workflows.
- Strong understanding of cybersecurity frameworks, attack techniques, and incident handling.
- Excellent analytical and communication skills.
Experience
- L3 SOC Lead / Senior Analyst 6 10+ years of Cyber Security / SOC experience.
- Advanced incident response, threat hunting, mentoring, and escalation management expertise.
Preferred Certifications
- Security+, CySA+, GCIH, GCIA, CEH, CISSP, CCSP, Azure Security, Splunk or CrowdStrike certifications.