About
Around 5 Years of hands-on Experience in Security Operations. Incident Response, Endpoint Security, Phishing analysis, Threat Intelligence, Network Security.
Skills & Expertise (71)
Work Experience
Security Analyst - SOC
Fujitsu
Feb 2021 - Present
Working in Security Operation Centre (24/7), monitoring of SOC events, Detecting and Preventing the Intrusion attempts. Monitor and triage alerts from SIEM platforms (Splunk, Sentinel, Elastic/ELK) by correlating data across endpoint (CrowdStrike, Defender), network, cloud (Zscaler, AWS, Azure), and email security tools. Worked for MNC clients, interacting directly with the customers, presenting SOC status reports and completing the action items according to client request. Real time monitoring of Network Security devices such IPS, Firewall, DLP, Endpoint Security, Operating system, and Email security, servers, VPN etc. Correlate logs from Zscaler Internet Access / ZPA to detect cloud-based threats. Performing the in-depth analysis to identify root cause of the incidents and performing malware analysis to identify behavior of the files. Analyzing the phishing emails which are reported by the employees to the SOC team and identifying whether the reported email is a phishing or spam or legitimate. Performing the phishing campaign and educating the employees. Having experienced in working FortiSOAR for SOAR playbook creation and monitoring alerts. Stay updated on latest CVEs, TTPs, and MITRE ATT&CK techniques to strengthen detection strategies.
Education
Bachelor of Technology - Ballari Institute of Technology And Management
- 2019 · Afghanistan
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Relocation
Open to Relocation