Perform L2 monitoring, triage, investigation, and response to security alerts and incidents in a 24x7 SOC environment.
Analyze and correlate logs from SIEM, EDR/XDR, firewalls, network devices, servers, cloud, identity, and security applications.
Investigate security incidents such as malware, phishing, compromised accounts, suspicious network activity, privilege escalation, lateral movement, and data exfiltration.
Conduct root-cause analysis, identify attack techniques/TTPs, and determine the scope and impact of incidents.
Perform threat hunting and proactively identify suspicious activities, IOCs, and emerging threats.
Create, validate, and tune SIEM correlation rules, detection use cases, and alerts based on organizational requirements.
Perform false-positive analysis and detection tuning to improve alert accuracy and SOC efficiency.
Analyze threat intelligence, vulnerabilities, IOCs, and TTPs and correlate them with internal security events.
Support investigation and response to critical and high-severity incidents, escalating complex cases to L3/Incident Response teams with complete evidence and analysis.
Coordinate with Network, Server, Cloud, IT, IAM, Vulnerability Management, and other technology teams for containment and remediation.
Monitor and validate the health and availability of critical security monitoring/log sources and report gaps or ingestion issues.
Prepare and maintain incident reports, investigation timelines, RCA, security advisories, and SOC documentation.
Maintain accurate incident records and updates on ServiceNow, ManageEngine or other ITSM platforms.
Develop and maintain SOC playbooks, SOPs, knowledge articles, and investigation procedures.
Use Python, PowerShell, Bash, or other scripting languages to automate repetitive SOC activities and analysis.
Perform basic network/packet analysis and investigate suspicious network communications.
Contribute to SOC dashboards, metrics, trend analysis, and management reporting.
Share investigation findings, threat intelligence, and lessons learned with other SOC analysts and security teams.