- Monitor security system, tools for alerts, and incidents
- Triage suspicious incidents to determine its severity and potential impact
- Take appropriate action to contain, mitigate, or resolve incidents to minimize damage and prevent further spread
- Investigate and analyze security incidents to determine their root cause and impact
- Collaborate with other security teams, such as threat intelligence and incident response, to resolve complex security incidents
- Document and report security incidents, investigations, and recommendations for improving security processes and controls
- Stay up to date with the latest security threats and trends
- Review and analyze security logs, alerts, and reports generated by various security tools, such as intrusion detection systems (IDS), firewalls, and antivirus software