About
SOC Analyst with 4 years of experience in enterprise security operations, specializing in SIEM (XSIAM), SOAR automation, EDR, and cloud security. Experienced in incident response, threat detection, and handling high-severity incidents in 24x7 environments. Proven track record of reducing MTTR, automating repetitive workflows, and improving SLA compliance. Strong communicator with expertise in reporting, documentation, and client engagement.
Skills & Expertise (23)
Work Experience
Senior Systems Engineer
Infosys
Aug 2022 - Present
Conducted proactive monitoring, triage of security alerts and performed log correlation in SIEM (XSIAM) to identify malicious activity using reports, dashboards, covering abnormal logins, malware callbacks (Firewall Management Center), malware prevention, and inbox rule mail forwards. Performed initial forensic triage during incident investigations using endpoint and log artifacts. Analyzed trends in security incidents and queried security logs using XQL to efficiently triage and investigate incidents. Investigated incidents using Azure AD logs, Microsoft Defender and endpoint telemetry from EDR/XDR platforms to ensure accurate event classification and whitelisting of legitimate processes. Possess hands-on knowledge of both Linux and Windows environments, and developed standard operating procedures (SOPs) to effectively mitigate security risks. Performed root cause analysis for escalated security incidents. Monitored potential security threats and assisted in documenting and validating disaster recovery procedures like abnormal logins, remediation procedures, windows methodologies, malware prevention/detection guides, incident reports. Conducted weekly health assessments and prepared the corresponding security report using Process Street. Performed real-time threat detection and incident response within the SOC, working closely with clients, customers, and external teams to ensure effective resolution of security incidents by blocking the threat indicators. Maintained incident root cause records and supported entries in internal security risk register. Coordinated patching and remediation activities with IT teams for pre and post-incident. Performed abuse analysis and investigation into suspicious behavior and potential fraud patterns within user activity logs. Using OSINT tools such as VirusTotal, URL Scan, Any Run, and DNSDumpster to enrich threat investigation efforts. Demonstrated in-depth understanding of OWASP Top 10 vulnerabilities and mitigation strategies, leveraged this knowledge to triage and escalate high-impact alerts during SOC investigations. Analyzed traffic and alerts involving standard, non-standard ports and IP address within the Firewall Management Center. Assisted SOC teams in whitelisting legitimate processes, ensuring accurate security event classification. Experienced in working across US shifts/Weekend Availability and responding to escalated incidents aligned with organizational security policies and compliance standards. Created IT support tickets via SysAid for Malwarebytes scans and remediation tasks. Engaged with customers regularly to understand requirements and improve incident investigation processes. Generated daily, weekly, and monthly incident reports for customer reference. Collaborated with the SOAR team to define and implement automation requirements for task optimization.
Education
Bachelor of Technology in Computer Science - Godavari Institute of Engineering and Technology
2018 - 2022 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (23)
Click a skill to find developers with the same skill