Overview
What I do
- Triage and mitigate alerts from the EDR/XDR platform, escalating and responding according to incident severity and response protocols
- Lead containment, investigation, and recovery once an incident is confirmed
- Support cloud security operations, including access control and audit-log monitoring
- Correlate cloud activity with endpoint telemetry to build a complete picture of an incident
- Produce incident documentation and evidence for leadership and regulators






