This role supports endpoint- and network-focused investigations across the internal environment. It is responsible for reviewing suspicious host activity, network anomalies, hostile connectivity patterns, remote access risks, and related operational threats. The role helps preserve solid traditional SOC coverage across infrastructure while supporting the SOC s maturity into a more fintech-/crypto-aware function.
Key Responsibilities
- Investigate endpoint-related alerts using CrowdStrike
- Review suspicious host behavior, including suspicious processes, execution anomalies, remote access behavior, and early indicators of compromise
- Investigate suspicious network or perimeter activity using FortiGate
- Review hostile inbound/outbound traffic, VPN anomalies, suspicious external access attempts, and network patterns that may indicate misuse
- Correlate endpoint incidents with Cloudflare edge activity to determine whether attacks originated externally
- Investigate suspicious outbound behavior, risky cloud access, or exfiltration-adjacent signals using Netskope
- Support endpoint isolation, containment,
and escalation workflows
- Correlate endpoint and network signals with IAM, email, and cloud events
- Recommend monitoring or hardening improvements based on recurring patterns
- 24 7 operations
Mandatory Expertise
- Endpoint and Network Security Operations
Note: Interested candidates may send their resume to
Disclaimer : This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.