Monitor SentinelOne MDR console for malware and ransomware alerts.
- Monitor Trend Micro Server Security health and malware events.
- Review Netskope DLP, Proxy and SWG alerts.
- Monitor privileged account activities from CyberArk.
- Monitor identity events from Skillmine IDAM and Active Directory.
- Validate endpoint policy compliance and security posture.
- Perform initial IOC validation and event correlation.
- Create, classify and assign incidents.
- Execute first-level containment (host isolation, account lock, IOC blocking) as per SOP.
- Maintain incident timelines and evidence.
- Verify AV signature and agent health.
- Generate Daily Security Operations Report and Shift Handover Report.