Job Description
Position
Executive Analyst - TDR
Location
Colombo, Sri Lanka
We are looking for a TDR Analyst to join our Security Operations Center (SOC) team. The ideal candidate will be responsible for monitoring security operations, triaging and investigating alarms, coordinating incident response, maintaining SLA compliance, and supporting continuous improvement of our detection and response capabilities.
Requirements
- Minimum 2 years of experience in SOC L1/L2 operations.
- Good understanding of security alert triage, threat analysis, and incident investigation.
- Familiarity with SIEM, SOAR/XSOAR, EDR, and other security monitoring platforms.
- Strong analytical, problem-solving, and decision-making skills.
- Ability to work effectively in a 24/7 shift-based SOC environment.
- Ability to follow established security procedures, playbooks, and escalation processes.
- Strong self-learning and continuous learning ability, with an interest in keeping up with emerging cybersecurity threats and technologies.
Responsibilities
- Shift Operations
- Conduct effective shift handovers and maintain open case documentation.
- Alarm Triage & Investigation
- Triage and investigate security alarms.
- Request customer information and document evidence, decisions, and timelines.
- Manage security cases and tickets.
- Customer Communication
- Communicate triage verdicts within SLAs.
- Obtain customer approval for required response actions.
- Escalation
- Escalate complex and confirmed incidents to the SecOps Consultant.
- Support DFIR escalations under SecOps Consultant direction.
- Notify customers of incidents requiring immediate action.
- Incident Response
- Execute approved manual response actions.
- Monitor automated response playbooks, exceptions, and outcomes.
- SLA Compliance
- Ensure compliance with defined SLAs for triage, communication, and response.
- Feedback & Continuous Improvement
- Identify false positives, missed detections, and detection issues.
- Recommend detection tuning and operational improvements to the SecOps Consultant.
- DFIR Support
- Assist with evidence collection, log retrieval, and timeline documentation under SecOps Consultant direction.
Application
Send your resume to: work@deltaspike.io