Summary
Overview
Work History
Education
Skills
Certification
Personal Information
Work Availability
Timeline
Desmond Ntah

Desmond Ntah

Washington,US

Summary

Dedicated SOC Analyst with 7 years of experience in threat detection, incident response, and security operations. Seeking to contribute expertise and leadership to a dynamic security team.

Overview

7
7
years of professional experience
1
1
Certification

Work History

Cybersecurity Administrator/Analyst

CRI
Chantilly , VA
05.2023 - Current

• Analyzed and correlated security data from various sources, including IDS/IPS, firewalls, and endpoint protection systems.

• Investigated intrusion attempts and performed in-depth analysis of exploits.

• Provide network intrusion detection expertise to support timely and effective decision making of when to declare an incident.

• Reviewed security events that are populated in a Security Information and Event Management (SIEM) system.

• Analyzed a variety of network and host-based security appliance logs (Firewalls, NIDS, HIDS, Sys Logs, etc.) to determine the correct remediation actions and escalation paths for each incident.

• Maintained and improved SOC documentation, including incident response playbooks and standard operating procedures.

• Collaborated with threat intelligence teams to stay updated on emerging threats and vulnerabilities, proactively implementing necessary countermeasures.

• Independently followed procedures to contain, analyze, and eradicate malicious activity.

• Documented all activities during an incident and provided leadership with status updates during the life cycle of the incident.

• Researched and tested new security tools/products and make recommendations of tools to be implemented in the SOC environment.

• Created a final incident report detailing the events of the incident.

• Participated in regular security drills and tabletop exercises to ensure effective incident response.

• Provided information regarding intrusion events, security incidents, and other threat indications and warning information to US government agencies.

Security Analyst

VOACC
Alexandria , VA
08.2018 - 05.2020

• Monitored and analyzed security alerts generated by SIEM tools to identify potential security incidents.

• Investigated alerts to determine the scope and severity of incidents.

• Documented and reported security incidents and breaches following established protocols.

• Ensure the SOC analyst team provides excellent customer service and support.

• Influenced and improved upon existing processes through innovation and operational change.

• Evaluated existing technical capabilities and systems and identified opportunities for improvement.

• Assisted in incident response activities, including containment and mitigation of threats.

• Collaborated with senior SOC analysts to escalate and manage complex security incidents.

• Interpreted information provided by tools to form a sound hypothesis regarding the root cause of an event.

• Performed incident response activities such as host triage and retrieval, malware analysis, remote system analysis, end-user interviews, and remediation efforts.

• Created new ways to solve existing production security issues.

• Monitored security events in the SIEM and other general office tools.

• Triaged incoming security events, performed analysis, and escalated to supervisors and customers if events deem additional response action.

• Monitored security appliance health and performed basic troubleshooting of security devices; notify security engineering as necessary for malfunctioning equipment.

• Provided 24x7 Operational support on a shift schedule (including overnight shifts and weekends).

• General network background including familiarity with OSI and TCP/IP models, ports and protocols, and Internet communications technologies (HTTP, DNS, SMTP, etc)

Oracle DBA

DROM
Lanham , MD
09.2016 - 09.2018

• Performed Installation and configuration of Oracle 11gR2 database on HP-UX platform.

• Successfully performed migrations from Oracle 10g/11g to 11gR2 RAC and 19c

• Performed space management, capacity planning, disaster recovery and overall maintenance of the databases.

• Used SQL TRACE, EXPLAIN PLAN utilities for optimizing and tuning SQL queries.

• Provided 24X7 support for all the production and development databases.

• Successfully performed data replication using Materialized views and Oracle Streams in Oracle 11gR2. • Cloned/Migrated databases using RMAN and traditional Data Pump export/import utilities in Oracle 11gR2.

• Perform RMAN operations (Incremental Backups). Helped developer to install Oracle Client, troubleshoot and establish the connection to Oracle database through ODBC, JDBC.

• Performance tuning for optimized results using tools like EXPLAIN PLAN, SQL*Trace, TKPROF, STATSPACK, AWR and ADDM reports.

• Database tuning, Application Tuning & performance monitoring. Fine tuning Initialization parameters, I/O, Memory and Operating System kernel parameters.

• Monitored the production Oracle alert logs for database errors and data issues.

• Used EXPORT/IMPORT to do table level and full database defragmentation.

• Performed patching of Oracle databases with latest patches from Oracle.

• Install and configure block change tracking to work with RMAN Merged incremental backups.

• Applied patches 10.2.0.2 and 10.2.0.3, 10.2.0.4.

• Responsible for Creating Users, Groups, Roles, Profiles and assigning the users to groups and grant necessary privileges to the relevant groups.

Education

Bachelor of Science in Information Systems -

University of Yaoundé

Computer Science

University of Yaoundé , Cameroon

Skills

  • Operating Systems: Windows Server 2008, 2012 2012R2, 2016, Linux, Macintosh and Android
  • Software: Microsoft 365 exchange admin, Gsuite, Solarwinds, pfsense, ServiceNow, Lansweeper, HashiCorp
  • Security Tools: Nessus, Logthrythm,Netskope,Vectra, Proofpoint, Okta, Crowdstrike, Malwarebytes, Duo, Splunk, Cylance, Fireeye HX, Ivanti, Wireshark, Carbon Black, Nmap and Palo Alto
  • Network: TCP/IP, router and switches configuration, Packet capturing(Pkap), Montoring and Wireshark
  • Remote tools: Windows Remote Desktop, PDQ Bomgar, AnyDesk and TeamViewer
  • Language: English, French and Spanish (intermediate)
  • Network and system monitoring
  • Threat intelligence analysis
  • Incident response procedures
  • Vulnerability assessment
  • Malware analysis
  • Firewall and access control
  • Security protocols and standards
  • Strong analytical and problem-solving skills
  • Excellent communication and teamwork abilities

Certification

  • CompTIA Security+, COMP001021700303, 11/2023
  • AWS Certified Solutions Architect, K5HJ587C3JV1QQCQ, 05/2024
  • Certified ScrumMaster, 000934808, 05/2021
  • Certified Oracle Professional, OC1791608, 07/2019
  • SQL Fundamentals
  • Splunk 7.x Fundamentals

Personal Information

Citizenship: US Citizen

Work Availability

monday
tuesday
wednesday
thursday
friday
saturday
sunday
morning
afternoon
evening
swipe to browse

Timeline

Cybersecurity Administrator/Analyst - CRI
05.2023 - Current
Security Analyst - VOACC
08.2018 - 05.2020
Oracle DBA - DROM
09.2016 - 09.2018
University of Yaoundé - Bachelor of Science in Information Systems,
University of Yaoundé - , Computer Science
  • CompTIA Security+, COMP001021700303, 11/2023
  • AWS Certified Solutions Architect, K5HJ587C3JV1QQCQ, 05/2024
  • Certified ScrumMaster, 000934808, 05/2021
  • Certified Oracle Professional, OC1791608, 07/2019
  • SQL Fundamentals
  • Splunk 7.x Fundamentals
Desmond Ntah