About this role
• Monitor SIEM, SOAR, and UEBA platforms on a 24×7 basis for security events and alerts. • Perform initial triage, validate security incidents, and classify alerts based on SOPs. • Monitor log collection, platform health, automation workflows, and data ingestion status. • Create and update incident tickets, maintain investigation records, and prepare operational reports. • Escalate confirmed security incidents, failed automation workflows, and anomalous user activities to the L2 team. • Coordinate with IT and security teams during incident response and service restoration. • Verify the successful execution of automated playbooks and security workflows. • Adhere to SOC processes, SLAs, escalation matrix, and documentation standards.