Key Responsibilities Monitor security alerts and events from SIEM, EDR/XDR, firewall, IDS/IPS, antivirus, email security, and other security tools . Perform real-time monitoring of security events in a 24×7 SOC setting . Investigate and triage security alerts based on severity, priority, and potential business impact. Identify false positives and distinguish them from genuine security incidents. Perform initial investigation and incident analysis using logs, alerts, endpoint data, and network activity. Analyze Indicators of Compromise (IOCs) such as IP addresses, domains, URLs, file hashes, and suspicious processes. Investigate common threats including: Phishing and malicious emails Malware and ransomware Brute-force attacks Unauthorized access