The Role
Monitor SIEM and analytics tools to acknowledge, analyze, validate, and escalate security incidents; collect logs for investigations; manage incident tracking, change requests and root cause analysis in ITSM; produce regular SIEM reports; analyze support ticket data and ticket quality, identify outliers, and recommend process improvements.
Summary Generated by Built In
The primary function of this role is to monitor the analytics tools and perform alert management and initial incident qualification. The responsibilities range from
monitoring, reporting and escalating incidents to SoC Analysts.
Key Responsibilities:
- Acknowledge, analyze and validate incidents triggered from correlated events through SIEM platform
- Acknowledge, analyze and validate incidents received through reporting tools/mechanisms
such as ticketing systems, phone, email….
- Collection of necessary logs that could help in
the incident containment and security investigation
- Escalate validated and flagged incidents to SOC Analyst
- Understand first stage off False positive and False negative
- Track and update incidents and requests based on incident findings and priority
- Proper logging of Change Requests and Root
Cause Analysis in the ITSM ticketing system
- Generate weekly/monthly reports from SIEM platform
Data Analytics
- to ensure that all the data is extracted and sorted from the support ticketing system
- to ensure that data is analyzed using various methods and tabulated
- to ensure that the outliers are identified, and necessary recommendations are made to help optimize the support
- to report
the analyzed data to the relevant stake holders.
Quality
- to ensure that the support tickets are complete in terms of content
- to ensure that the support tickets are profiled correctly for data analysis.
- to analyze the gaps in ticket quality and identify the outliers
- to ensure the necessary recommendations are made to improve the quality of tickets
Process Analytics
- to ensure that the support process currently
Skills Required
- Experience monitoring and managing alerts in a SIEM platform
- Experience using ITSM/ticketing systems for incident tracking, change requests, and RCA
- Ability to collect and analyze logs to support incident containment and investigation
- Skill in acknowledging, validating, and escalating incidents to SOC analysts
- Understanding of false positives and false negatives in alerting
- Experience generating weekly/monthly reports from SIEM or analytics tools
- Ability to extract, analyze, and tabulate support ticket data and report findings to stakeholders
- Experience assessing and improving support ticket quality and profiling
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
VST Global is a global IT company providing strategic business solutions and services to solve problems of all scales across multiple industry sectors, tailoring consulting services to unique business needs.








