Frontline role within the Global Security Operations Center (GSOC) monitoring IT IDS, SIEM, and XDR queues to validate alerts, enrich findings with environment context (asset role, zone/level, recent change activity, vendor session status, and user identity history), and execute low-risk first-response actions under approved playbooks (e.g., end remote sessions, disable stale vendor accounts, block known malicious indicators, and quarantine phishing-affected endpoints). This role maintains site-aware shift logs and high-quality handoffs, flags telemetry gaps, and builds foundational OT/IT awareness through cross-training.