Incident Investigation & Response: Perform Tier 1/2 security event triage, incident analysis, root cause investigation, and threat remediation recommendations across endpoint, identity, network, and cloud environments.
MSSP Platform & Onboarding: Support customer onboarding, SIEM / EDR / MDR log integration, and detection policy tuning (e.g., Microsoft Sentinel, Defender, CrowdStrike).
Operational Execution: Execute daily security operations in alignment with SLAs, playbooks, and runbooks; escalate complex threats to Central Cybersecurity SMEs.
...