Summary
Overview
Work History
Education
Skills
Timeline
Generic

SHALEENA EVANS

Atlanta

Summary

Personal attributes: dedication, integrity, and strong work ethic. A fast learner that adapts well to new challenges and job requirements. Able to approach extreme challenges with composure and clarity. Well organized, detail oriented and efficient. Able to plan, prioritize and complete multiple tasks in a thorough, efficient & accurate manner. Extremely service oriented and self-starting individual with a strong track record of success in problem solving skills. Confident, articulate, and persuasive team-builder able to motivate and communicate effectively to maintain integrity of mission and vision while achieving exceptional business performance.

Overview

18
18
years of professional experience

Work History

Security Analyst

Jaguar Containers
Atlanta
02.2014 - Current
  • Receiving alerts from IPS (FireEye), DLP (Symantec), EDR (Carbon Black, Crowdstrike), TAP Alerts (ProofPoint) I conduct investigations to determine if there is anything suspicious or malicious from the notifications coming from the list of security tools, so that they can be remediated or flagged as false positives.
  • Correlate events and gathering more information to make determinations in SIEM (QRadar)

Security Analyst

Finish Line
Atlanta
10.2013 - 07.2014
  • Assist analyst investigation and ticket creation efforts. Provide daily monitoring and alerting of events that occur within the near real time environment.
  • Manage the SOC mailbox, and monitor and analyze the emails for threats including phishing and malware, escalates per procedure.
  • Monitor, evaluate, and assist with the maintenance of assigned security systems in accordance with industry best practices to safeguard internal information systems and databases.
  • Stay informed of current events in the security industry including the latest exploits and threats as well as preventative measures, remediation, and restoration techniques.
  • Oversee and ensure P1 and P2 incidents are handled according to operational procedures. Document areas of improvement through after-action reports and work with necessary parties to resolve any findings.
  • Identify improvements within processes, procedures, policies, staffing, training, and tools to improve efforts and daily operations.
  • Assist in developing and maturing the future services and capabilities of the SOC, using Qradar SIEM, Carbon black EDR, ProofPoint Email gateway, Checkpoint Firewalls and other security tools.
  • Investigated endpoints using SentinelOne and successfully terminated and deleted possible malicious file and processes.

Call Center Representative

Alorica
Saraland
06.2012 - 10.2013
  • Respond to CSIRT mailbox, escalating and remediating incidents.
  • Create objects and rules from request for Checkpoint Firewalls; placing SAM blocks on IPs that are scanning the network.
  • Using Bluecoat Reporter, scheduled reports malicious botnets, application downloads and potential infections.
  • Monitor and investigate TAP alerts from Proofpoint. Remediating malware infections through virus scans using McAfee Anti-virus and tools such as Virustotal, Malwr and others to investigate malware alerts. Respond to phishing alerts.
  • Use ProofPoint to blacklist email addresses block senders and IP addresses associated with SPAM. Monitor spoofing and geo-location folders for suspicious email.
  • Checking shared drives for PII and escalate for quarantine or mark as false positive with McAfee DLP. Now using Symantec DLP.
  • Monitor security events and logs from a variety of sources including firewalls, network and data at rest DLP, IDS/IPS, network devices, system logs, and other data feeds in order to detect security anomalies, provide analysis and respond with appropriate mitigation to prevent a security incident.
  • Interface with Security Risk Management and provide detailed analysis and information on applicable weaknesses and vulnerabilities.
  • Perform UAC or Entitlement review, using Sailpoint, making sure users have the correct permissions to perform their job functions ensuring least privilege.
  • Using Qualys we are scanning and reporting to different teams the vulnerabilities they may have. Checking to see if there are any compensating controls in place and to make sure patching stays on schedule.
  • Remediate and respond to Carbon Black alerts to files that are blocked, creating and tuning policy.
  • Investigate and remediate escalations from MSSP, Secureworks.
  • SIEM: Tibco Loglogic / QRadar

SOC Analyst

Kathy's Cut & Style
Mobile
08.2008 - 10.2013
  • Perform analysis of log files. Includes analysis of system resource access using Arcsight and Checkpoint Smartview Tracker also firewall health checks.
  • Monitor network security events received from alerts in Sourcefire IDS/IPS and Alertlogic, and then take appropriate action based on security policy. Also monitoring the network for any anomalies and malicious/suspicious activity.
  • Perform vulnerability scans of devices sitting on the network using Qualys, gather reports and determine security levels from QID’s.
  • Blocking/blacklisting URL’s on the Bluecoat proxy, check proxy health and traffic.
  • Strong analytical and problem solving skills.
  • Incident response using Remedy ticketing system and Alarmpoint notifications to join bridges to remediate incidents.
  • Investigate and remediate SOC tickets from Dell Secureworks.

Education

Full Stack Web Development - Certified

4 Geeks Academy
Remote

High School Diploma -

John L Leflore Magnet
Mobile

Skills

  • SIEM
  • EDR
  • IDS/IPS
  • DLP
  • Vulnerability Management
  • Continuous monitoring

Timeline

Security Analyst

Jaguar Containers
02.2014 - Current

Security Analyst

Finish Line
10.2013 - 07.2014

Call Center Representative

Alorica
06.2012 - 10.2013

SOC Analyst

Kathy's Cut & Style
08.2008 - 10.2013

Full Stack Web Development - Certified

4 Geeks Academy

High School Diploma -

John L Leflore Magnet
SHALEENA EVANS