Job Summary
Key Responsibilities
Monitoring & Detection
- Monitor security events, alerts, and logs from SIEM tools (e.g., Splunk, QRadar, ArcSight).
- Perform real-time monitoring of network traffic, systems, and applications.
- Analyze alerts generated by IDS/IPS, firewalls, antivirus, and other security tools.
✅ Incident Analysis
- Investigate suspicious activities and identify potential security incidents.
- Perform Level 1 / Level 2 triage and determine severity and impact.
- Correlate multiple events to identify attack patterns.
✅ Escalation & Response
- Escalate confirmed incidents to higher-level teams (L2/L3, IR team).
- Follow predefined incident response procedures (IR playbooks).
- Document incidents and maintain detailed logs.
✅ Network Operations Monitoring
- Monitor network performance, uptime, and connectivity issues.
- Identify anomalies such as unusual traffic spikes or unauthorized access attempts.
- Work closely with NOC teams for operational issues.
✅ Reporting & Documentation
- Prepare daily/weekly reports on:
- Security incidents
- Network alerts
- SLA adherence
- Maintain incident tracking systems (ServiceNow, Jira, etc.).
✅ Compliance & Security Practices
- Ensure adherence to security policies, standards, and compliance requirements (ISO 27001, SOC 2, etc.).
- Assist in audits and security assessments.
Skill Requirements
2. Strong Understanding Of It Support Processes And Incident Management Frameworks.
3. Familiarity With Security Best Practices And Technical Troubleshooting Methodologies.
4. Excellent Analytical And Problem-Solving Skills, With The Ability To Work Under Pressure.
5. Effective Communication And Collaboration Skills To Liaise With Multiple Support Teams.