- Manage alert detection, incident triage, investigation and response activities.
- Serve as a subject matter expert (SME) for SOC tools and processes.
- Perform in-depth analysis of complex security events and indicators of compromise (IOCs).
- Develop and maintain playbooks, runbooks, and incident response procedures.
- Mentor and train L1 and L2 SOC analysts and foster a collaborative team workplace.
- Collaborate with IT, risk management, compliance and business units during investigations and threat assessments.
- Tuning and optimization of SIEM platforms (e.g. Azure Sentinel, LogRhythm, Splunk, QRadar, Wazuh etc.) and threat detection rules.
- Integrate threat intelligence feeds and contextual analysis to enrich SOC capabilities.
- Support red team/blue team exercises and vulnerability assessments.
- Ensure timely and accurate incident reporting and documentation.