Monitor SentinelOne MDR console for malware and ransomware alerts.
Monitor Trend Micro Server Security health and malware events.
Review Netskope DLP, Proxy and SWG alerts.
Monitor privileged account activities from CyberArk.
Monitor identity events from Skillmine IDAM and Active Directory.
Validate endpoint policy compliance and security posture.
Perform initial IOC validation and event correlation.
Create, classify and assign incidents.
Execute first-level containment (host isolation, account lock, IOC blocking) as per SOP.
Maintain incident timelines and evidence.
Verify AV signature and agent health.
Generate Daily Security Operations Report and Shift Handover Report.