ROLES & RESPONSIBILITIES
- Reviews alerts generated by SentinelOne and implement appropriate containment and mitigation measures
- Analyzes payloads using JoeSandbox and escalates to the appropriate team as necessary
- Collaborates with the Forensics team to conduct threat hunting using identified Indicators of Compromise (IoCs) and Tactics, Techniques, and Procedures (TTPs)
- Assists the Tiger Team in targeted collections of systems based on identified malicious activities in the client's workplace
- Conducts historical log reviews to support threat hunting efforts and ensures all malicious artifacts are mitigated in the SentinelOne console
- Examines client-provided documents and files to supplement the SOC investigation and mitigation strategy
- Stays up to date on the latest Threat Actor Tactics, Techniques and Procedures (TTPs)
- Conducts perimeter scans of client infrastructure and reports any identified vulnerabilities to the Tiger Team for appropriate escalation
- Manages client-related tasks within the ConnectWise Manage ticketing system as part of the Client Handling Lifecycle
- Creates user accounts in SentinelOne console for the client
- Generates Threat Reports showcasing activity observed within the SentinelOne product
- Execute passphrase exports as needed for client offboarding
- Submit legacy installer requests to ensure the team is properly equipped for deployment
- Provides timely alert notifications to the IR team of any malicious activity impacting our clients
- Assists with uninstalling/migrating SentinelOne
- Generates Ranger reports to provide needed visibility into client environments
- Manages and organizes client assets (multi-site and multi-group accounts)
- Applies appropriate interoperability exclusions relating to SentinelOne and client applications
- Performs SentinelOne installation / interoperability troubleshooting as needed
- Contributes to the overall documentation of SOC processes and procedures
- Investigates alerts escalated