
Key Tasks & Responsibilities:
Monitor and investigate cloud‑application‑related security alerts generated by Microsoft Defender for Cloud Apps (MDCA) under defined CSOC processes.
Perform alert triage and initial investigation to determine scope, user impact, risk level, and business relevance.
Support investigation of incidents involving risky cloud apps, OAuth abuse, data exposure, suspicious user activity, and abnormal cloud access patterns.
Assist in containment and remediation activities in coordination with Identity, Endpoint, Email, and IT platform teams.
Escalate complex or high‑risk cloud‑app security findings to L2/L3 specialists or Incident Managers with structured analysis and evidence.
Analyze user behavior, activity logs, and cloud telemetry to identify anomalies and suspicious activity.
Support policy tuning, alert refinement, and basic detection improvements to reduce false positives and improve signal quality.
Assist with shadow IT discovery, cloud app risk assessments, and enforcement of cloud app governance policies.
Support CSOC playbooks, runbooks, and response procedures related to cloud application security incidents.
Participate in post‑incident reviews and RCA discussions, contributing operational findings and improvement ideas.
Maintain accurate investigation notes, incident documentation, and response records.
Work closely with CSOC L1/L2 analysts, Identity, Endpoint, Email Security, and IT operations teams.
Support audit and compliance activities related to cloud application security controls when required.
Key Skills:
Hands‑on experience with Microsoft Defender for Cloud Apps (MDCA).
Understanding of cloud application risks, SaaS security concepts, and user activity monitoring.
Basic working knowledge of the Microsoft Defender ecosystem (MDE, MDO, Sentinel – awareness level).
Understanding of SOC operations, alert triage, investigation workflows, and escalation models.
Familiarity with incident response lifecycle and CSOC processes.
Basic experience correlating cloud‑app alerts with identity, endpoint, or email‑based signals.
Foundational knowledge of cybersecurity concepts such as access control, identity security, data protection, malware, phishing, and attack chains.
Awareness of frameworks such as MITRE ATT&CK and basic threat‑actor techniques.
Understanding of risks related to cloud usage, OAuth permissions, and SaaS data exposure.
Basic understanding of cloud identity concepts (users, roles, permissions).
Familiarity with authentication, authorization, and session‑based access risks in cloud apps.
Ability to analyze logs, user activity, and audit events for investigation purposes.
Bachelor’s degree in computer science, Information Technology, Cybersecurity, or Engineering.
2 – 4 years of cybersecurity experience, with exposure to SOC operations, cloud security, or security monitoring roles.
Hands‑on experience or operational exposure to Microsoft Defender for Cloud Apps is required.
Experience supporting low to medium‑severity cloud or SaaS security incidents in enterprise environments is preferred.
Certifications:
SC‑200: Microsoft Security Operations Analyst

Daimler Truck North America, a Daimler Truck AG company, is the largest heavy-duty truck manufacturer in North America and a leading producer of medium-duty trucks and specialized commercial vehicles.
Headquartered in Portland, Oregon, Daimler Truck North America manufactures, sells and services several renowned commercial vehicle brands including Freightliner Trucks, Western Star Trucks, Thomas Built Buses, and Freightliner Custom Chassis. Through the company’s affiliates, Daimler Truck North America is also a leading provider of heavy-and medium-duty diesel engines and other components. The company’s strategic partners in the North American commercial vehicles market include Daimler Truck Financial, TravelCenters of America and Petro Truck Centers.