- Monitor SIEM dashboards and alerts for Claude Code anomalies (unusual prompt volumes, DLP triggers, auth failures).
- Investigate and triage security events; escalate confirmed incidents.
- Develop and refine SIEM detection rules for AI-specific threat scenarios (prompt injection attempts, data exfiltration patterns).
- Conduct daily audit log reviews; produce weekly security metrics report.
- Participate in incident response exercises and tabletops (AI-specific scenarios).
- Maintain SOC runbooks for Claude Code incident response.
- 3+ years in a SOC or security monitoring role.
- Proficiency with Splunk, Microsoft Sentinel, or IBM QRadar.
- Solid analytical and investigation skills.
- Familiarity with MITRE ATTACK framework.
- Understanding of API security and web traffic analysis.