Level 1 – MDR Analyst (Monitoring & Initial Response)
Level 1 Analysts form the first line of defense within the 24×7×365 Managed Detection & Response operation.
They are responsible for continuous monitoring, initial triage, and escalation of alerts generated by
SentinelOne EDR, FortiSIEM, and FortiSOAR platforms are integrated with UEBA.
Monitor security alerts, dashboards, and telemetry from SentinelOne, FortiSIEM, and UEBA in real time.
Perform initial triage and classification of incidents based on severity and potential impact.
Follow standard operating procedures for alert validation and escalate verified incidents to Level 2 Analysts.
Execute predefined containment actions (e.g., isolate endpoints, disable users, block IPs) via FortiSOAR playbooks.
Maintain incident documentation, ticketing, and SLA compliance using FortiSOAR’s native ticketing system.
Generate and deliver daily and shift summary reports covering key detections and trends.
Support KnowBe4 phishing incident reporting workflows and initiate phishing alert escalations.
Required Skills & Experience
1–2 years of SOC or MDR operations experience.
Working knowledge of SentinelOne or similar EDR, SIEM dashboards, and SOAR tools.
Basic understanding of network and endpoint security fundamentals.
Strong attention to detail, communication, and shift-handoff discipline.