About the role
Overview WELCOME TO SITA
At SITA, we keep airports moving, airlines flying smoothly, and borders open. Our technology and communication innovations power the success of the global air travel industry.
You’ll find us in 95% of international airports, working closely with over 2,500 transportation and government clients. Each partnership brings unique challenges, and we thrive on delivering fresh solutions and cutting-edge tech to keep operations running like clockwork. We don’t just move the world forward, we’re proud to be recognized as a Great Place to Work® by our employees and certified in most of our growing locations.
Here, we feel empowered, supported, and inspired to grow.
Are you ready to love your job? The adventure begins right here, with you, at SITA.
ABOUT THE ROLE & TEAM
Perform investigations and validation of security alerts and incidents to ensure accurate threat identification and response. Continuously improve detection quality and monitoring effectiveness while providing mentorship and guidance to SOC analysts. Drive operational excellence within the SOC by enhancing processes, strengthening investigative capabilities, and ensuring the timely identification, analysis, and escalation of security incidents to the Security Incident Response Team (SIRT).
WHAT YOU WILL DO
Act as the primary escalation point for junior SOC Analysts, providing expert guidance and oversight during security investigations.
Lead complex security incident investigations, validating alert classification, severity, scope, and escalation decisions.
Conduct advanced threat analysis and correlation across SIEM, EDR/XDR, cloud, identity, network, and endpoint environments.
Collect, analyze, and document evidence, developing investigation timelines and technical findings to support incident response activities.
Collaborate with SIRT and cross-functional technical teams, ensuring timely escalation of confirmed or suspected security incidents.
Develop, optimize, and maintain detection rules, correlation logic, SOC use cases, investigation playbooks, and alert tuning activities.
Identify detection gaps, monitoring deficiencies, and false-positive trends, applying the M…