Managed detection on the vendor's own telemetry, which means you see the raw signal rather than a summary. Shift work with proper handover, and a strong bias toward writing detections instead of clearing the same alert twice.
What you will do
- Triage and investigate endpoint and cloud detections
- Escalate confirmed intrusions with a explicit timeline
- Propose detection improvements from what you saw
What they ask for
- Understanding of Windows and Linux process behaviour
- Able to read a command line and say why it is suspicious
- Willing to work a rotating shift
Nice to have
- Detection engineering experience
- Sigma or KQL