Responsibilities
Responsible for 24x7 monitoring of SIEM alerts and security events, performing initial alert triage, identifying potential security incidents, and escalating confirmed or suspicious events to L2/L3 teams within defined SLAs.
Monitor SIEM dashboards, alerts, events and security incidents on a 24x7 basis.
Perform L1 alert triage and validate security events.
Analyze logs from Firewall, WAF, Proxy, EDR, Windows/Linux, AD, DNS, VPN, Email Security and other security devices.
Identify True Positive (TP) and False Positive (FP) alerts.
Perform initial investigation of suspicious IPs, domains, URLs, hashes, users and hosts.
Correlate events from multiple log sources to identify potential threats.
Escalate confirmed/suspicious incidents to L2/L3 as per the defined escalation matrix.
Create and update tickets with complete investigation details and evidence.
Ensure alerts and incidents are handled within defined SLA/KPI timelines.
Maintain proper shift handover and communicate all pending/high-priority incidents.
Follow documented SOPs, playbooks and escalation procedures.
Support daily SOC reports, incident reports and shift reports.
Monitor SIEM health, log source connectivity and report ingestion issues to the respective teams.
Participate in incident response, vulnerability-related investigations and security investigations as required.
Maintain confidentiality and follow organizational security policies.