TeamPlus
2. Continuously monitor and triage alerts from EDR, SIEM, and
firewall systems;
perform event correlation and threat analysis.
3. Investigate, contain, and remediate security incidents following
standard
playbooks (incident lifecycle management).
4. Conduct log analysis and prepare detailed incident reports,
including root
cause analysis and mitigation steps.
5. Manage and optimize firewall, proxy, and VPN configurations
(Meraki or
similar).
6. Review and update security baselines, policies, and group
policies across
Microsoft 365 and Azure AD.
7. Manage email security gateways (Proofpoint, Mimecast, or
Microsoft
Defender for 365), anti-phishing and spam filtering rules.
8. Perform vulnerability scanning using Tenable, Qualys, or open-
source tools
and assist in patch management closure.
9. Execute periodic compliance and security posture checks (CIS
Benchmarks,
NIST, ISO 27001 readiness).
10. Conduct backup integrity checks, DR test simulations, and
data recovery
drills using CloudBerry/MSP360 or similar tools.
11. Develop PowerShell scripts for automation of repetitive
monitoring and alert
triage tasks.
12. Maintain and update cybersecurity dashboards and
documentation for audits
and management reviews.