- Continuously monitor customer environments for alerts generated via Microsoft Sentinel and Microsoft Defender XDR
- Perform initial investigation and validation of alerts to determine legitimacy and potential impact.
- Conduct threat assessment and contextual analysis using available telemetry, logs, and threat intelligence.
- Classify and prioritize alerts based on severity, asset criticality, and business impact.
- Execute first-level response actions as per approved SOPs and playbooks (e.g., containment, enrichment, ticket updates) to mitigate the risk and resolve the alert.
- Log explicit justification for actions taken, ensuring traceability and audit readiness
- Identify false positives and reduce alert noise through structured validation and coordination with L2 team.
- Regularly update and maintain the SOPs, Runbooks and Playbooks based on analysis and investigation outcomes.
- Provide detailed feedback and recommendations to L2 SOC for rule tuning and optimization
- Escalate incidents to Tier 2 / Tier 3 / Onshore SOC based on severity and impact
- Provide comprehensive shift handover with full technical and operational context
- Coordinate with onshore SOC, incident response, engineering, and customer teams during escalations
- Perform post-fix monitoring to confirm service stability
- Maintain accurate incident records, timelines, evidence, audit trails, and CI updates in the ticketing system