Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Nearshore profiles role detail

Each profile is mobilized on a precise scope of your security operations, with its own level of responsibility and autonomy.

SOC analysts — levels N1, N2, N3

The monitoring chain is organized across three levels, each with a distinct role in handling alerts.

N1 — Triage and qualification

Receiving and first-pass sorting of alerts, filtering out obvious false positives, escalating uncertain cases to N2.

N2 — Investigation and escalation

In-depth analysis of escalated alerts, correlation across sources, deciding whether to qualify as an incident and escalating to N3 when needed.

N3 — Threat hunting and tuning

Proactive hunting for threats not caught by existing rules, tuning detection rules, handling the most complex incidents.

Detection engineers

They design and maintain the detection capability day to day.

  • Writing and maintaining detection rules (Sigma, EDR, SIEM)
  • Mapping coverage against the MITRE ATT&CK framework
  • Reducing false-positive volume through continuous tuning
  • Monitoring emerging attack techniques that need coverage

Security auditors

They assess the organizational and technical security posture of a given scope.

  • Interviews with technical teams and governance
  • Configuration review of systems and equipment
  • Gap analysis against the applicable framework
  • Drafting the audit report and a prioritized remediation plan

Pentesters

They run penetration tests to identify exploitable vulnerabilities.

  • Reconnaissance and mapping of the attack surface
  • Controlled exploitation of identified vulnerabilities, within the authorized scope
  • Detailed documentation of the exploitation path for each finding
  • Technical debrief and remediation recommendations

GRC consultants

They support the structuring of security governance and regulatory compliance.

  • Risk analysis and prioritization based on business impact
  • Drafting and maintaining governance documentation (policies, procedures)
  • Tracking compliance action plans
  • Preparation for certification or regulatory audits

Cloud security engineers

They secure public and hybrid cloud environments end to end.

  • Configuration review of cloud services (IAM, network, storage)
  • Detecting misconfigurations and excessive access rights
  • Implementing security controls native to the cloud provider
  • Supporting DevOps teams on secure practices