Summary
Overview
Work History
Education
Skills
Personal Information
Certification
Languages
Activities
ADDITIONAL INFORMATION
Timeline
Generic
Ayhan Aytac

Ayhan Aytac

Irvine

Summary

Dynamic Security Analyst with proven expertise at SAIC in automating threat response and enhancing incident detection through advanced SIEM tools like Splunk,MS Sentinel and CrowdStrike. Skilled in vulnerability assessment and incident response, I effectively reduced false positives by 25% while mentoring junior analysts to elevate team performance.

Overview

8
8
years of professional experience
5
5
Certification

Work History

Security Analyst

SAIC
04.2022 - Current
  • Integrated EDR solutions (CrowdStrike, Defender for Endpoint) with SIEM pipelines to automate threat response through SOAR playbooks.
  • Utilized Python to analyze large volumes of security logs and detect anomalies across endpoint, network, and cloud environments.
  • Logged and tracked security incidents using IT ticketing systems, ensuring complete and accurate documentation for each case.
  • Investigated and contained security incidents involving phishing, credential theft, and lateral movement; produced detailed post-incident reports.
  • Collaborated with cross-functional IT teams to investigate and resolve security issues efficiently.
  • Developed Python scripts to automate repetitive SOC tasks such as alert triage, log parsing, and IOC enrichment, improving incident response speed and analyst efficiency.
  • Generated routine and ad-hoc security reports, ensuring timely and accurate delivery to stakeholders.
  • Collaborated with SOC teams to develop and test new correlation rules based on MITRE ATT&CK techniques.
  • Adhered to and maintained SOC Service Level Agreements (SLAs) for timely security alert response and resolution.

Security Analyst

Cognizant Technologies
07.2021 - 03.2022
  • Developed and maintained custom Splunk searches, reports, and dashboards to facilitate proactive threat hunting and incident detection.
  • Conducted regular tuning of Splunk alerts and queries to reduce false positives and enhance detection accuracy.
  • Followed detailed operational processes and procedures to appropriately analyze, escalate, and assist in remediation of security incidents.
  • Experience with EDR solutions including Carbon Black, SentinelOne, FireEyeHX, CrowdStrike.
  • Experience analyzing log and packet data in a SIEM Azure Sentinel.
  • Documented and maintained detailed case logs and incident reports for phishing incidents.
  • Conducted regular security assessments and audits using Prisma Cloud's scanning and threat detection capabilities, identifying and mitigating risks related to misconfigurations, vulnerabilities, and anomalous activities.
  • Managed Data Loss Prevention (DLP) tools and enforced incident response processes to prevent data exfiltration.
  • Developed and updated comprehensive Cybersecurity Incident Response Plans, with 2+ years of experience in modernizing IR strategies.
  • Delivered advanced cybersecurity expertise and leadership, effectively resolving complex issues in Incident Response, Threat Intelligence, GRC, Privacy, Vulnerability Management, and Engineering Operations.
  • Performed analysis of log files of Firewall, IPS, IDS, Server, and Proxy via the Splunk SIEM solution.
  • Created and tracked incidents and requests with an integrated ServiceNow (SNOW) ticketing and automation system.
  • Analyzed pcap files for malware analysis and identified details of infected hosts, writing IOCs for executive summary reports.

SOC Analyst

Solvent
Raleigh, North Carolina
08.2018 - 08.2021
  • Monitored enterprise environments using SIEM platforms (Splunk) to identify, investigate, and escalate suspicious activities in real time.
  • Analyzed logs from firewalls, proxies, EDR, and email gateways to detect anomalies, malware, and unauthorized access attempts.
  • Tuned detection rules and correlation logic to reduce false positives by 25%, and improve alert accuracy.
  • Performed triage on alerts related to brute-force attacks, phishing, data exfiltration, and privilege escalation.
  • Managed email threat queues and quarantine requests through Proofpoint and Microsoft Exchange Online Protection, reducing the average response time by 30%.
  • Generated daily and weekly SOC metrics reports on incident volume, response time, and closure rates.

Education

Masters Degree - Cyber Security

National University
San Diego, CA
02.2023

Skills

  • Vulnerability assessment
  • Cloud security
  • Risk analysis
  • Endpoint security
  • ProofPoint, CrowdStrike
  • SIEM tools (Splunk, Sentinel)
  • Malware analysis
  • Incident response
  • Data loss prevention
  • Documentation management
  • Data security
  • Identity and Access management

Personal Information

Title: Cybersecurity Analyst

Certification

  • CEH (2022)
  • CySA+ (2023)
  • Security+ (2021)
  • Azure Administrator (AZ-104, 2023)
  • AWS Cloud Practitioner (2024)

Languages

English, Turkish

Activities

OSINT Summit SANS Community Events Austin summit cybersecurity

ADDITIONAL INFORMATION

  • SIEM: Microsoft Sentinel, Splunk
  • EDR: CrowdStrike, SentinelOne, Carbon Black,Cylance
  • Email Security: Proofpoint, Mimecast,Symantec
  • Cloud: Azure, AWS, Prisma Cloud
  • Incident Response: Triage, Phishing, Forensics, Root Cause Analysis
  • Frameworks: NIST, MITRE ATT&CK
  • Ticketing: ServiceNow, Jira

Timeline

Security Analyst

SAIC
04.2022 - Current

Security Analyst

Cognizant Technologies
07.2021 - 03.2022

SOC Analyst

Solvent
08.2018 - 08.2021

Masters Degree - Cyber Security

National University
Ayhan Aytac