Key Responsibilities Incident Detection & Response • Monitor and investigate security alerts from Taegis, Defender as well as user or third-party reported incidents. • Perform initial triage and analysis of suspicious events and potential security incidents. • Determine incident severity, scope, and business impact. • Contain security incidents through actions such as: o Account disablement o Password resets o Session revocation o Device isolation o IP and domain blocking • Escalate complex or high-severity incidents to senior security personnel. Investigation & Analysis • Analyze endpoint, network, identity, and cloud telemetry. • Correlate indicators of compromise (IOCs) with threat intelligence sources. • Identify root causes and attack vectors. • Conduct malware investigations and support forensic analysis activities. • Track attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK;. Incident Documentation • Maintain detailed incident records and case documentation. • Create incident reports detailing findings, actions taken, and business impact. • Ensure evidence is collected, preserved, and documented appropriately. • Participate in post-incident reviews and lessons-learned sessions. Collaboration • Coordinate with IT Operations, Service Desk, Infrastructure, Network, and Cloud teams during investigations. • Communicate incident status to stakeholders and management. • Support major incident response activities and virtual war room operations during significant security events. Continuous Improvement • Contribute to development of SOC playbooks and response procedures. • Recommend improvements to detection rules, monitoring coverage, and response workflows. • Assist in threat hunting and security control validation activities. • Stay current with emerging threats, vulnerabilities, and industry best practices. Required Qualifications Education • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or equivalent experience. Experience • 2–5+ years of cybersecurity, SOC, incident response, or security operations experience. • Experience investigating security incidents in enterprise environments. • Familiarity with Windows, Linux, cloud platforms, and enterprise networking. Technical Skills • SIEM technologies • EDR/XDR platforms (Taegis , Microsoft Defender, CrowdStrike, SentinelOne, etc.) • Email security technologies • Identity platforms such as Active Directory and Entra ID
Key Responsibilities Incident Detection & Response • Monitor and investigate security alerts from Taegis, Defender as well as user or third-party reported incidents. • Perform initial triage and analysis of suspicious events and potential security incidents. • Determine incident severity, scope, and business impact. • Contain security incidents through actions such as: o Account disablement o Password resets o Session revocation o Device isolation o IP and domain blocking • Escalate complex or high-severity incidents to senior security personnel. Investigation & Analysis • Analyze endpoint, network, identity, and cloud telemetry. • Correlate indicators of compromise (IOCs) with threat intelligence sources. • Identify root causes and attack vectors. • Conduct malware investigations and support forensic analysis activities. • Track attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK;. Incident Documentation • Maintain detailed incident records and case documentation. • Create incident reports detailing findings, actions taken, and business impact. • Ensure evidence is collected, preserved, and documented appropriately. • Participate in post-incident reviews and lessons-learned sessions. Collaboration • Coordinate with IT Operations, Service Desk, Infrastructure, Network, and Cloud teams during investigations. • Communicate incident status to stakeholders and management. • Support major incident response activities and virtual war room operations during significant security events. Continuous Improvement • Contribute to development of SOC playbooks and response procedures. • Recommend improvements to detection rules, monitoring coverage, and response workflows. • Assist in threat hunting and security control validation activities. • Stay current with emerging threats, vulnerabilities, and industry best practices. Required Qualifications Education • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or equivalent experience. Experience • 2–5+ years of cybersecurity, SOC, incident response, or security operations experience. • Experience investigating security incidents in enterprise environments. • Familiarity with Windows, Linux, cloud platforms, and enterprise networking. Technical Skills • SIEM technologies • EDR/XDR platforms (Taegis , Microsoft Defender, CrowdStrike, SentinelOne, etc.) • Email security technologies • Identity platforms such as Active Directory and Entra ID
: Key Responsibilities Incident Detection & Response • Monitor and investigate security alerts from Taegis, Defender as well as user or third-party reported incidents. • Perform initial triage and analysis of suspicious events and potential security incidents. • Determine incident severity, scope, and business impact. • Contain security incidents through actions such as: o Account disablement o Password resets o Session revocation o Device isolation o IP and domain blocking • Escalate complex or high-severity incidents to senior security personnel. Investigation & Analysis • Analyze endpoint, network, identity, and cloud telemetry. • Correlate indicators of compromise (IOCs) with threat intelligence sources. • Identify root causes and attack vectors. • Conduct malware investigations and support forensic analysis activities. • Track attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK;. Incident Documentation • Maintain detailed incident records and case documentation. • Create incident reports detailing findings, actions taken, and business impact. • Ensure evidence is collected, preserved, and documented appropriately. • Participate in post-incident reviews and lessons-learned sessions. Collaboration • Coordinate with IT Operations, Service Desk, Infrastructure, Network, and Cloud teams during investigations. • Communicate incident status to stakeholders and management. • Support major incident response activities and virtual war room operations during significant security events. Continuous Improvement • Contribute to development of SOC playbooks and response procedures. • Recommend improvements to detection rules, monitoring coverage, and response workflows. • Assist in threat hunting and security control validation activities. • Stay current with emerging threats, vulnerabilities, and industry best practices. Required Qualifications Education • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or equivalent experience. Experience • 2–5+ years of cybersecurity, SOC, incident response, or security operations experience. • Experience investigating security incidents in enterprise environments. • Familiarity with Windows, Linux, cloud platforms, and enterprise networking. Technical Skills • SIEM technologies • EDR/XDR platforms (Taegis , Microsoft Defender, CrowdStrike, SentinelOne, etc.) • Email security technologies • Identity platforms such as Active Directory and Entra ID
Responsibilities Incident Detection & Response • Monitor and investigate security alerts from Taegis, Defender as well as user or third-party reported incidents. • Perform initial triage and analysis of suspicious events and potential security incidents. • Determine incident severity, scope, and business impact. • Contain security incidents through actions such as: o Account disablement o Password resets o Session revocation o Device isolation o IP and domain blocking • Escalate complex or high-severity incidents to senior security personnel. Investigation & Analysis • Analyze endpoint, network, identity, and cloud telemetry. • Correlate indicators of compromise (IOCs) with threat intelligence sources. • Identify root causes and attack vectors. • Conduct malware investigations and support forensic analysis activities. • Track attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK;. Incident Documentation • Maintain detailed incident records and case documentation. • Create incident reports detailing findings, actions taken, and business impact. • Ensure evidence is collected, preserved, and documented appropriately. • Participate in post-incident reviews and lessons-learned sessions. Collaboration • Coordinate with IT Operations, Service Desk, Infrastructure, Network, and Cloud teams during investigations. • Communicate incident status to stakeholders and management. • Support major incident response activities and virtual war room operations during significant security events. Continuous Improvement • Contribute to development of SOC playbooks and response procedures. • Recommend improvements to detection rules, monitoring coverage, and response workflows. • Assist in threat hunting and security control validation activities. • Stay current with emerging threats, vulnerabilities, and industry best practices. Required Qualifications Education • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or equivalent experience. Experience • 2–5+ years of cybersecurity, SOC, incident response, or security operations experience. • Experience investigating security incidents in enterprise environments. • Familiarity with Windows, Linux, cloud platforms, and enterprise networking. Technical Skills • SIEM technologies • EDR/XDR platforms (Taegis , Microsoft Defender, CrowdStrike, SentinelOne, etc.) • Email security technologies • Identity platforms such as Active Directory and Entra ID

HCLTech is a global technology company, home to more than 226,600 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending September 2025 totaled $14.2 billion. To learn how we can supercharge progress for you, visit hcltech.com.