Daimler Truck Banner Image contains multiple vehicles that represent each company

DTICI_Cloud App Security Engineer (MDCA)_T9_consultant

Key Tasks & Responsibilities: 

  • Monitor and investigate cloudapplicationrelated security alerts generated by Microsoft Defender for Cloud Apps (MDCA) under defined CSOC processes.

  • Perform alert triage and initial investigation to determine scope, user impact, risk level, and business relevance.

  • Support investigation of incidents involving risky cloud apps, OAuth abuse, data exposure, suspicious user activity, and abnormal cloud access patterns.

  • Assist in containment and remediation activities in coordination with Identity, Endpoint, Email, and IT platform teams.

  • Escalate complex or highrisk cloudapp security findings to L2/L3 specialists or Incident Managers with structured analysis and evidence.

  • Analyze user behavior, activity logs, and cloud telemetry to identify anomalies and suspicious activity.

  • Support policy tuning, alert refinement, and basic detection improvements to reduce false positives and improve signal quality.

  • Assist with shadow IT discovery, cloud app risk assessments, and enforcement of cloud app governance policies.

  • Support CSOC playbooks, runbooks, and response procedures related to cloud application security incidents.

  • Participate in post‑incident reviews and RCA discussions, contributing operational findings and improvement ideas.

  • Maintain accurate investigation notes, incident documentation, and response records.

  • Work closely with CSOC L1/L2 analysts, Identity, Endpoint, Email Security, and IT operations teams.

  • Support audit and compliance activities related to cloud application security controls when required.

 

Key Skills:

  • Handson experience with Microsoft Defender for Cloud Apps (MDCA).

  • Understanding of cloud application risks, SaaS security concepts, and user activity monitoring.

  • Basic working knowledge of the Microsoft Defender ecosystem (MDE, MDO, Sentinel – awareness level).

  • Understanding of SOC operations, alert triage, investigation workflows, and escalation models.

  • Familiarity with incident response lifecycle and CSOC processes.

  • Basic experience correlating cloudapp alerts with identity, endpoint, or emailbased signals.

  • Foundational knowledge of cybersecurity concepts such as access control, identity security, data protection, malware, phishing, and attack chains.

  • Awareness of frameworks such as MITRE ATT&CK and basic threatactor techniques.

  • Understanding of risks related to cloud usage, OAuth permissions, and SaaS data exposure.

  • Basic understanding of cloud identity concepts (users, roles, permissions).

  • Familiarity with authentication, authorization, and sessionbased access risks in cloud apps.

  • Ability to analyze logs, user activity, and audit events for investigation purposes.

Key Tasks & Responsibilities: 

  • Monitor and investigate cloudapplicationrelated security alerts generated by Microsoft Defender for Cloud Apps (MDCA) under defined CSOC processes.

  • Perform alert triage and initial investigation to determine scope, user impact, risk level, and business relevance.

  • Support investigation of incidents involving risky cloud apps, OAuth abuse, data exposure, suspicious user activity, and abnormal cloud access patterns.

  • Assist in containment and remediation activities in coordination with Identity, Endpoint, Email, and IT platform teams.

  • Escalate complex or highrisk cloudapp security findings to L2/L3 specialists or Incident Managers with structured analysis and evidence.

  • Analyze user behavior, activity logs, and cloud telemetry to identify anomalies and suspicious activity.

  • Support policy tuning, alert refinement, and basic detection improvements to reduce false positives and improve signal quality.

  • Assist with shadow IT discovery, cloud app risk assessments, and enforcement of cloud app governance policies.

  • Support CSOC playbooks, runbooks, and response procedures related to cloud application security incidents.

  • Participate in post‑incident reviews and RCA discussions, contributing operational findings and improvement ideas.

  • Maintain accurate investigation notes, incident documentation, and response records.

  • Work closely with CSOC L1/L2 analysts, Identity, Endpoint, Email Security, and IT operations teams.

  • Support audit and compliance activities related to cloud application security controls when required.

 

Key Skills:

  • Handson experience with Microsoft Defender for Cloud Apps (MDCA).

  • Understanding of cloud application risks, SaaS security concepts, and user activity monitoring.

  • Basic working knowledge of the Microsoft Defender ecosystem (MDE, MDO, Sentinel – awareness level).

  • Understanding of SOC operations, alert triage, investigation workflows, and escalation models.

  • Familiarity with incident response lifecycle and CSOC processes.

  • Basic experience correlating cloudapp alerts with identity, endpoint, or emailbased signals.

  • Foundational knowledge of cybersecurity concepts such as access control, identity security, data protection, malware, phishing, and attack chains.

  • Awareness of frameworks such as MITRE ATT&CK and basic threatactor techniques.

  • Understanding of risks related to cloud usage, OAuth permissions, and SaaS data exposure.

  • Basic understanding of cloud identity concepts (users, roles, permissions).

  • Familiarity with authentication, authorization, and sessionbased access risks in cloud apps.

  • Ability to analyze logs, user activity, and audit events for investigation purposes.

  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or Engineering.

  • 2 – 4 years of cybersecurity experience, with exposure to SOC operations, cloud security, or security monitoring roles.

  • Handson experience or operational exposure to Microsoft Defender for Cloud Apps is required.

  • Experience supporting low to mediumseverity cloud or SaaS security incidents in enterprise environments is preferred.

  • Certifications:

    • SC‑200: Microsoft Security Operations Analyst

  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or Engineering.

  • 2 – 4 years of cybersecurity experience, with exposure to SOC operations, cloud security, or security monitoring roles.

  • Handson experience or operational exposure to Microsoft Defender for Cloud Apps is required.

  • Experience supporting low to mediumseverity cloud or SaaS security incidents in enterprise environments is preferred.

  • Certifications:

    • SC‑200: Microsoft Security Operations Analyst

At Daimler Truck, we promote diversity and foster an inclusive corporate culture. We value the individual strengths of our employees, as these lead to the best team performance and thus to the success of our company. Inclusion and Equal opportunities are important to us – regardless of where you come from and who you are. We look forward to receiving applications from people of all cultures and genders, parents, people with disabilities and people from the LGBTIQ+ community.
At Daimler Truck, we promote diversity and foster an inclusive corporate culture. We value the individual strengths of our employees, as these lead to the best team performance and thus to the success of our company. Inclusion and Equal opportunities are important to us – regardless of where you come from and who you are. We look forward to receiving applications from people of all cultures and genders, parents, people with disabilities and people from the LGBTIQ+ community.
DAIMLER TRUCK CAREER FACEBOOK DAIMLER TRUCK CAREER INSTAGRAM