Tactical Threat Analyst 2 (MDR)
CurrentMay 2023 – Present
Managed Detection and Response (MDR) · FortiEDR · Monitoring · Threat hunting · Incident response
- Work as part of Fortinet’s MDR team, monitoring FortiEDR alerts across customer environments and investigating suspicious activity on endpoints.
- Handle alerts end to end in FortiSOAR — reviewing the activity, filtering out false positives, and escalating confirmed threats to customers with clear findings and recommended actions.
- Investigate endpoint incidents by tracing process trees, command lines, parent-child relationships, and other available telemetry to understand what happened and determine the scope of the activity.
- Respond to confirmed threats by isolating affected endpoints, stopping malicious processes, removing persistence, and supporting customers through remediation.
- Perform threat hunting across customer environments using threat intelligence, new IOCs, and known attacker techniques to identify activity that may not have triggered existing detections.