About
Security Operations Center (SOC) Analyst with 3+ years of experience in 24×7 enterprise environments, specializing in SIEM monitoring, alert triage, and incident validation. Experienced in handling high-volume security alerts using Splunk and Sophos EDR within banking and financial infrastructures. Skilled in phishing investigation, authentication anomaly detection, and structured incident documentation using ServiceNow.
Skills & Expertise (21)
Work Experience
Network Support Associate
Wipro
Nov 2021 - Jan 2023
Monitored network alerts using enterprise monitoring tools and logged incidents for timely investigation. Performed first-level troubleshooting for connectivity issues by verifying IP configuration, basic reachability (ping), and DNS resolution. Followed predefined troubleshooting runbooks to resolve common network-related incidents. Ensured accurate documentation of troubleshooting steps and resolution details in ServiceNow while adhering to SLA timelines. Escalated unresolved or complex issues to L2 network engineers with proper incident context and logs.
Security Operations Analyst
Wipro
Feb 2023 - Present
Monitor and investigate high-volume security alerts in a 24×7 SOC using Splunk SIEM, detecting suspicious authentication activity, endpoint threats, and network anomalies. Analyze Windows and Linux security logs to identify brute-force attempts, privilege misuse, and potential system compromise. Conduct endpoint threat investigations using Sophos EDR, reviewing process execution, command activity, and endpoint telemetry to validate incidents. Investigate phishing emails by examining headers, URLs, and attachments, contributing to early detection of targeted phishing attempts. Performed incident investigations involving brute-force attacks, abnormal outbound connections, malware alerts, and suspected account compromise, distinguishing true incidents from false positives. Correlate logs from firewalls, proxies, IDS/IPS, and authentication sources to distinguish true positives from false positives. Support monitoring of cloud environments, identifying suspicious access patterns and user behavior. Applied basic threat intelligence sources to validate malicious IPs and domains during investigations. Executed predefined incident response playbooks for authentication, malware, and phishing alerts. Document findings and evidence in ServiceNow, escalating confirmed incidents to L2/L3 teams for containment and remediation.
Education
Computer Systems - Bits-pilani
2022 - 2025 · Afghanistan
Bachelor of Computer Science - University of Adikavi Nannaya
2018 - 2021 · Afghanistan
Higher Secondary Education - Board of Intermediate Education Andhra Pradesh
2016 - 2018 · Afghanistan
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Relocation
Open to Relocation