Role & responsibilities
Manage alert detection, incident triage, investigation and response activities.
Serve as a subject matter expert (SME) for SOC tools and processes.
Perform in-depth analysis of complex security events and indicators of compromise (IOCs).
Develop and maintain playbooks, runbooks, and incident response procedures.
Mentor and train L1 and L2 SOC analysts and foster a team-oriented team workplace.
Collaborate with IT, risk management, compliance and business units during investigations and threat assessments.
Tuning and optimization of SIEM platforms (e.g. Azure Sentinel, LogRhythm, Splunk, QRadar, Wazuh etc.) and threat detection rules.
Integrate threat intelligence feeds and contextual analysis to enrich SOC capabilities.
Support red team/blue team exercises and vulnerability assessments.
Ensure timely and accurate incident reporting and documentation.