About
Senior Security Analyst with 3+ years of experience in the MSSP Operations, specializing in SIEM, EDR, WAF, Firewall, IDS, and IPS platforms. Proven expertise across Security Analysis, Security Engineering, Threat Hunting, Vulnerability Management, and Incident Response, with hands-on experience leading Incident Response Management for critical security events. Skilled in developing RCA documentation and SOPs to strengthen operational resilience, while supporting 24/7 security operations to safeguard enterprise infrastructure.
Skills & Expertise (30)
Work Experience
Senior Security Analyst
Teleperformance
Aug 2023 - Present
Working as a Senior Security Analyst, supporting multiple MSSP clients across different industries. Continuously monitoring security alerts and incidents across SIEM, EDR, XDR, IDS/IPS, firewalls, WAF, DLP, proxy, and cloud security platforms. Investigating, prioritizing, and responding to security incidents within the agreed SLA timelines. Performing advanced investigations involving phishing, malware, suspicious user activity, endpoint threats, network attacks, and cloud security incidents. Conducting static and dynamic malware analysis, along with endpoint forensic investigations using CrowdStrike Real-Time Response (RTR). Performing threat hunting based on IOCs, emerging threat advisories, and hypothesis-driven hunting techniques. Creating and fine-tuning Microsoft Sentinel analytics rules and use cases using logs from Cloudflare and other security platforms. Developing Microsoft Sentinel automation rules and playbooks for actions such as endpoint isolation, IOC blocking, and user account disabling. Creating dashboards and workbooks in Microsoft Sentinel and Cloudflare to monitor security events, traffic patterns, operational performance, and emerging threats. Reviewing Microsoft Defender for Endpoint and Microsoft Defender for Cloud Secure Scores and coordinating remediation activities to improve the organization’s security posture. Collaborating with internal teams and SMEs to block malicious IOCs, isolate endpoints, disable compromised accounts, restart affected systems, and implement long-term remediation measures. Performing vulnerability assessments using Nessus, Wiz, and other security tools to identify critical vulnerabilities, including remote code execution risks. Prioritizing vulnerabilities using CVSS scores, asset criticality, threat intelligence, and business impact, and tracking remediation with the relevant SMEs. Managing AWS security alerts generated by Amazon GuardDuty and AWS Security Hub and coordinating appropriate investigation and remediation actions. Creating and managing Conditional Access policies in the Microsoft Entra admin center, including authentication controls for Windows Hello for Business, FIDO2 security keys, and Microsoft Authenticator. Preparing incident response documents, including incident timelines, root-cause analyses, lessons learned, identified control gaps, and corrective action plans. Preparing daily, weekly, and monthly security reports and presenting operational performance, incident trends, risks, and remediation updates to senior management, including Directors and Vice Presidents. Applying security frameworks and methodologies such as MITRE ATT&CK, Cyber Kill Chain, ISO 27001, CIS Controls, and SOX requirements during investigations and security improvement activities.
Education
B.com (Computers) - GITAM Degree College
- 2022 · Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Citizen
Relocation
Open to Relocation
Skills (30)
Click a skill to find developers with the same skill