Performed frontline alert triage and investigations for clients across Windows, Linux, and multi-cloud infrastructures (AWS, Azure, GCP).
Investigated endpoint compromise, lateral movement, suspicious PowerShell activity, credential access attempts, persistence mechanisms, and anomalous cloud identity/API behavior using SIEM, SOAR, and EDR.
Coordinated with analysts to document and improve response workflows, contributing to playbook standardization and detection-as-code initiatives.
Collaborated with detection engineers to design and tune detections across multiple telemetry sources to reduce false positives and increase coverage against evolving threat techniques.