Monitor Security Information and Event Management (SIEM) dashboards and security monitoring tools for potential threats and suspicious activities.
Perform initial alert triage and escalate security incidents to senior analysts in accordance with established incident response procedures.
Analyze network security events, logs, and alerts from firewalls, intrusion detection/prevention systems (IDS/IPS), endpoint protection, and other security technologies.
Assist in vulnerability scanning activities and support remediation validation for identified security weaknesses.
Support incident response activities by documenting findings, collecting evidence, and maintaining incident records.
Assist in preparing security reports, dashboards, compliance documentation, and operational metrics.
Support security advisory activities by responding to user security inquiries and promoting cybersecurity awareness.
Collaborate with infrastructure, network, cloud, and application teams to investigate and resolve security issues.
Participate in routine security health checks, access reviews, and compliance monitoring activities.
Maintain security documentation, standard operating procedures (SOPs), and knowledge base articles.