Job descriptionAdminister and maintain Trend Micro Vision One , Apex One , Deep Security , and TMEMS platforms.Monitor and respond to alerts, incidents, and threat intelligence from Trend Micro tools.Perform policy configuration, tuning, and updates across endpoint, server, and email security platforms.Conduct root cause analysis and threat hunting using Vision One’s XDR capabilities.Deep-dive into incidents escalated from L1 to confirm true positives and execute containment / remediation actions (e.g., block malicious IPs, isolate endpoints, disable compromised accounts).Lead playbook execution, enrichment, and automation of incident workflows.Perform Root Cause Analysis (RCA) and escalate complex cases to L3 when necessary.Provide remediation guidance to IT / business teams and support incident recovery.Tune alerts and detection rules to reduce false positives and improve detection accuracy.Generate and present detailed security reports, dashboards, and metrics to stakeholders.Collaborate with SOC teams to support incident response, threat mitigation, and major IR activities.Leverage tool-specific expertise (e.g., Zscaler , Wiz , CyberArk ) for advanced incident handling.Review vulnerability scan results and recommend remediation / mitigation steps.Identify SOC workflow / process improvement opportunities and suggest enhancements.Maintain detailed documentation for configurations, procedures, incident handling, and compliance-ready reporting.Mentor and support the upskilling of L1 SOC Analysts.Stay updated on emerging threats and Trend Micro product enhancements.