
Highly skilled Sr. Cyber Security Analyst with over 9+ years of experience in Security Operations Centre (SOC) environments. Specialized in threat hunting, incident response, and policy auditing within SIEM platforms. Proficient in Microsoft 365 security products and experienced in mentoring and developing SOC analysts. An analytical problem solver with a proven track record of implementing proactive measures, resulting in a significant reduction in security incidents. Holds a Bachelor's degree in Computer Science and currently studying for a master's in cyber security and information assurance. Committed to staying updated with the latest cybersecurity trends to ensure continuous improvement in security practices. Fluent in English.
• Assist in handling escalated computer security incidents and cyber investigations, encompassing computer and network forensics, root cause analysis, and malware analysis.
• Recognize areas requiring updates in data security policies and procedures, guiding and training team members accordingly.
• Collaborate with Information Security teams, risk officers, and technology management to shape cybersecurity strategy.
• Document assessment findings on security control implementation, conducting risk assessments based on control status and examination results.
• Act as a coordinator for escalated cyber threats/incidents, ensuring adherence to policies and regulatory requirements.
• Utilize XSOAR for investigating common security threats and work on enhancing security monitoring tools with contextual information.
• Deliver cyber intelligence services and insights to IT and business leaders, identifying new threat tactics used by cyber actors.
• Manage real-time monitoring of third-party security feeds, forums, and mailing lists, utilizing Splunk to investigate threats in the network environment.
• Utilize Netflow analysis, Gigamons, and HPNA for operational support and monitoring of the network infrastructure.
· Led and participated in Incident Response for SOC customers, covering Threat Detection, Response, and Remediation. Served as incident commander, effectively communicated issues, and provided recommendations for resolutions. Developed timelines and provided companywide updates during incidents, following disaster recovery procedures. Monitored phishing emails, investigated malware threats, and analyzed malware impact via Splunk and IronPort. Established disaster recovery procedures for SOC team, conducting monthly testing and training. Conducted security control and risk assessments based on security policies and best practices. Analyzed daily reports through NORSE SIEM and Netcool monitoring system for potential threats. Utilized Carbon Black to monitor user activities and restrict access based on vulnerability and impact analysis. Continuously assessed, tested, and implemented new security technologies to enhance network security.
· Supported internal and external users through troubleshooting, issue escalation, and deploying hardware/software.
· Assisted with installations, upgrades, and provided advanced troubleshooting for Windows and Mac OS.
· Identified and recommended upgrades to IT and communications infrastructure.
· Collaborated with unit personnel on infrastructure development.
· Addressed performance and capacity issues.
· Provided onsite and remote technical support.
· Managed equipment installations, removals, and monitored network infrastructure.
· Utilized ticketing systems Remedy and ServiceNow for documentation and issue resolution.
CompTIA Security+
Certified Ethical Hacker (CEH)
Certified AWS Cloud Solutions Architect
Certified Information Security Manager (CISM)
Microsoft Security Operations Analyst SC200