Security Operations & Incident Response
• Lead investigation, containment, remediation, and post-incident review of cybersecurity incidents across endpoint, identity, email, cloud, and network environments
• Investigate suspicious activity using SIEM, EDR/XDR, identity, email security, and other enterprise security telemetry
• Develop incident timelines, determine scope and root cause, document findings, and communicate risk and recommended actions to technical and leadership stakeholders
• Perform proactive threat hunting and identify opportunities to improve detection and response coverage
• Serve as an escalation point and mentor for other security analysts during complex investigations
Detection, SIEM & Automation
• Develop, tune, and improve security detections and correlation logic based on threats, incidents, and observed control gaps
• Use enterprise SIEM platforms to investigate threats, hunt across security telemetry, and improve monitoring coverage
• Support security orchestration and automation use cases, including playbooks for investigation, enrichment, containment, and notification
• Identify repetitive SOC processes that can be automated or streamlined
Endpoint, Identity & Cloud Threat Detection
• Investigate endpoint threats using CrowdStrike Falcon or comparable enterprise EDR/XDR platforms
• Investigate identity-based attacks involving Active Directory, Microsoft Entra ID, authentication, privileged accounts, OAuth applications, and session/token abuse
• Analyze Microsoft 365 and cloud security events and work with engineering and infrastructure teams on containment and remediation
• Use threat intelligence and indicators of compromise to scope incidents and proactively hunt for related activity
Data Security & DLP
• Support and improve enterprise DLP and data security monitoring across endpoint, email, cloud, and collaboration platforms
• Investigate potential data-loss, sensitive-data exposure, and policy-violation events and coordinate appropriate response
• Assist with tuning DLP policies and workflows to improve detection quality while reducing unnecessary business impact
• Partner with security, privacy, legal, and business stakeholders as appropriate during sensitive-data investigations
Cyber Defense Program Improvement
• Identify gaps discovered through incidents, threat hunting, and operational analysis and recommend practical improvements
• Develop and maintain investigation procedures, response playbooks, and operational documentation
• Collaborate with Security Engineering, IAM, Network, Cloud, and other technology teams to strengthen preventive and detective controls
• Take ownership of assigned Cyber Defense technologies or operational capabilities and drive their continued maturity