- Lead advanced investigation and response for security incidents identified through EDR SIEM SOAR and Threat Intelligence platforms
- Perform in depth endpoint analysis to detect malware persistence mechanisms privilege escalation lateral movement and other advanced threats
- Conduct malware analysis and reversing to identify Indicators of Compromise IOCs attack techniques and remediation actions
- Drive incident response activities including containment eradication recovery root cause analysis and post incident reviews
- Perform proactive threat hunting across enterprise endpoints leveraging behavioral analytics and threat intelligence
- Develop tune and optimize EDR detections response playbooks and automated containment workflows
- Collaborate with SOC Detection Engineering Threat Intelligence and Infrastructure teams to strengthen endpoint security posture
- Document investigations lessons learned and recommendations to enhance detection and response capabilities
- Stay current with emerging threats ransomware trends attack techniques and advancements in EDR technologies
Technology->Infrastructure Security->SOC Operations,Technology->Infrastructure Security->Security Incident and Event Management (SIEM)