Shift analyst owning end-to-end L1 triage across the engagement's detection surface — cloud audit (GCP/GKE), identity (Okta), WAF (Cloudflare), network flow (Cilium/Hubble), infrastructure and PKI events — with quality escalations into L2.
Key Roles & Responsibilities:
- Triage and investigate Exaforce detections; correlate across log sources and enrich with threat intelligence.
- Execute approved containment steps (block requests, token disablement) under L2/L3 authority matrix.
- Maintain alert-quality feedback: false-positive tagging and tuning suggestions into the detection backlog.
- Meet MTTA/MTTD SLAs; keep Linear tickets audit-grade. • Author and refresh triage runbooks; coach trainee analysts on shift.
- Coordinate with the NOC shift on cross-domain events (network anomaly vs security incident).
Mandatory Qualifications:
- BE/BTech (CS/IT/E&TC;) or equivalent.
- 2–4 years in a SOC/MSSP environment with hands-on triage ownership.
- Working experience on at least one enterprise SIEM (e.g., Cortex XSIAM, Chronicle, Splunk, Sentinel); quick ramp to Exaforce expected.
- MITRE ATT&CK-aligned; investigation method; log fluency across firewall, identity, and cloud audit sources.
- Disciplined ITSM/ticketing practice and written communication.