About
Cybersecurity professional with 2+ years of experience in Security Operations (SOC), transitioning into Governance, Risk, and Compliance (GRC). Skilled in incident analysis, threat detection, and identifying control gaps aligned with business risk. Strong knowledge of ISO/IEC 27001:2022, risk assessment methodologies, and compliance frameworks. Experienced in audit support, security documentation, and policy implementation.
Skills & Expertise (29)
Work Experience
Cyber Security Analyst (MSSP)
Laya Tech Pvt Ltd
Jan 2024 - Feb 2026
Supported implementation and operation of cybersecurity infrastructure, including firewalls, IDS/IPS, endpoint protection, and OS-level security controls in collaboration with engineers and architects. Performed 24/7 security monitoring and incident response using SIEM platforms, including alert triage, log correlation, root cause analysis, and escalation for threats such as malware, authentication failures, and anomalous activity. Conducted vulnerability assessments and penetration testing using tools like Nessus, Rapid7, Nexpose, Nmap, Metasploit, and Burp Suite; identified risks, recommended remediation, and validated fixes. Managed security operations and governance tasks, including log integration (Windows, Linux, AWS, Azure), technical security reviews, report generation, policy support, and troubleshooting network protocols (TCP/IP, DNS, HTTP, SSH, SMB).
SOC Analyst L2
Navitas Life Sciences Private Limited
Feb 2026 - Present
Monitored and analyzed security events using SIEM and EDR tools including Wazuh, Seceon, CrowdStrike, and Microsoft Defender; performed alert triage, correlation, and TP/FP validation. Conducted endpoint and email security operations, including threat investigations and remediation via CrowdStrike, and phishing detection and containment using Trellix. Executed data protection and vulnerability management activities using Microsoft Purview, Netskope, Ionix, and ManageEngine Endpoint Central, ensuring risk detection, patching, and remediation tracking. Supported governance, risk, and compliance initiatives, including ISO/IEC 27001 ISMS implementation, audits, reporting, security awareness programs, and alignment with frameworks like NIST Cybersecurity Framework and DPDP.
Education
Bachelor of Technology (B.Tech) – Information Security & Digital Forensics - Dr. M.G.R Educational and Research Institute University
- · Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Citizen
Relocation
Depends on Offer
Skills (29)
Click a skill to find developers with the same skill