Source description
About the role
Key Tasks & Responsibilities: Monitor and investigate cloudapplicationrelated security alerts generated by Microsoft Defender for Cloud Apps (MDCA) under defined CSOC processes. Perform alert triage and initial investigation to determine scope, user impact, risk level, and business relevance. Support investigation of incidents involving risky cloud apps, OAuth abuse, data exposure, suspicious user activity, and abnormal cloud access patterns. Assist in containment and remediation activities in coordination with Identity, Endpoint, Email, and IT platform teams. Escalate complex or highrisk cloudapp security findings to L2/L3 specialists or Incident Managers with structured analysis and evidence. Analyze user behavior, activity logs, and cloud telemetry to identify anomalies and suspicious activity. Support policy tuning, alert refinement, and basic detection improvements to reduce false positives and improve signal quality. Assist with shadow IT discovery, cloud app risk assessments, and enforcement of cloud app governance policies. Support CSOC playbooks, runbooks, and response procedures related to cloud application security incidents. Participate in postincident reviews and RCA discussions, contributing operational findings and improvement ideas. Maintain accurate investigation notes, incident documentation, and response records. Work closely with CSOC L1/L2 analysts, Identity, Endpoint, Email Security, and IT operations teams. Support audit and compliance activities related to cloud application security controls when required. Key Tasks & Responsibilities: Monitor and investigate cloudapplicationrelated security alerts generated by Microsoft Defender for Cloud Apps (MDCA) under defined CSOC processes. Perform alert triage and initial investigation to determine scope, user impact, risk level, and business relevance. Support investigation of incidents involving risky cloud apps, OAuth abuse, data exposure, suspicious user activity, and abnormal cloud access patterns. Assist in containment and remediation activities in coordination with Identity, Endpoint, Email, and IT platform teams. Escalate complex or highrisk cloudapp security findings to L2/L3 specialists or Incident Managers with structured analysis and evidence. Analyze user behavior, activity logs, and cloud telemetry to identify anomalies and suspicious activity. Support policy tuning, alert refinement, and basic detection improvements to reduce false positives and improve signal quality. Assist with shadow IT discovery, cloud app risk assessments, and enforcement of cloud app governance policies. Support CSOC playbooks, runbooks, and response procedures related to cloud application security incidents. Participate in postincident reviews and RCA discussions, contributing operational findings and improvement ideas. Maintain accurate investigation notes, incident documentation, and response records. Work closely with CSOC L1/L2 analysts, Identity, Endpoint, Email Security, and IT operations teams. Support audit and compliance activities related to cloud application security controls when required.
More at Daimler Truck
Related open roles
DTICI_IAM_ActiveDirectory_Senior Conultant_ (Bengaluru)
Bangalore
Vehconnectivity productowner Bizapplications (Bengaluru)
Bangalore
DTICI_Cloud App Security Engineer (MDCA)__consultant (Bengaluru)
Bangalore
Engineering_Data_Analysis_Engineer_T9
Bangalore
DTICI_Data scientist - Innovation and AI_T7
Bangalore