* Reviews alerts generated by SentinelOne and implement appropriate containment
and mitigation measures
* Analyzes payloads using JoeSandbox and escalates to the appropriate team as
necessary
* Collaborates with the Forensics team to conduct threat hunting using
identified Indicators of Compromise (IoCs) and Tactics, Techniques, and
Procedures (TTPs)
* Assists the Tiger Team in targeted collections of systems based on identified
malicious activities in the client's setting
* Conducts historical log reviews to support threat hunting efforts and ensures
all malicious artifacts are mitigated in the SentinelOne console
* Examines client-provided documents and files to supplement the SOC
investigation and mitigation strategy
* Stays up to date on the latest Threat Actor Tactics, Techniques and
Procedures (TTPs)
* Conducts perimeter scans of client infrastructure and reports any identified
vulnerabilities to the Tiger Team for appropriate escalation
* Manages client-related tasks within the ConnectWise Manage ticketing system
as part of the Client Handling Lifecycle
* Creates user accounts in SentinelOne console for the client
* Generates Threat Reports showcasing activity observed within the SentinelOne
product
* Execute passphrase exports as needed for client offboarding
* Submit legacy installer requests to ensure the team is properly equipped for
deployment
* Provides timely alert notifications to the IR team of any malicious activity
impacting our clients
* Assists with uninstalling/migrating SentinelOne
* Generates Ranger reports to provide needed visibility into client
environments
* Manages and organizes client assets (multi-site and multi-group accounts)
* Applies appropriate interoperability exclusions relating to SentinelOne and
client applications
* Performs SentinelOne installation / interoperability troubleshooting as
needed
* Contributes to the overall documentation of SOC processes and procedures
* Investigates alerts escalate