About
SOC Analyst with 4 years of experience in Security Operations Center (SOC), Security Monitoring, Threat Detection, Incident Response, and Cybersecurity Operations. Experienced in monitoring enterprise environments using Microsoft Sentinel and IBM QRadar, investigating endpoint threats using CrowdStrike Falcon and Microsoft Defender for Endpoint, and handling phishing, malware, ransomware, brute-force, and account compromise incidents. Skilled in SIEM administration, KQL query development, threat hunting, vulnerability management, Active Directory, MITRE ATT&CK framework, and security incident lifecycle management. Strong knowledge of cloud security, endpoint protection, and security best practices with the ability to deliver timely incident response while maintaining SLA compliance.
Skills & Expertise (31)
Work Experience
SOC Analyst
Sonata Software
Jan 2022 - Oct 2025
Monitored security events and alerts using Microsoft Sentinel and IBM QRadar in a 24ร7 Security Operations Center. Investigated security incidents related to malware, phishing, ransomware, brute-force attacks, suspicious logins, endpoint compromise, and account takeover. Performed incident triage, investigation, containment, eradication, recovery, and closure following established incident response procedures. Investigated endpoint threats using CrowdStrike Falcon and Microsoft Defender for Endpoint. Conducted phishing investigations using Proofpoint and Microsoft Defender for Office 365. Developed and optimized SIEM detection rules and KQL queries to improve threat detection and reduce false positive alerts. Performed threat hunting activities using security logs, endpoint telemetry, and threat intelligence feeds. Mapped attacker techniques using the MITRE ATT&CK Framework and Cyber Kill Chain methodology. Conducted malware analysis, IOC validation, and root cause analysis for confirmed security incidents. Managed incidents through ServiceNow while ensuring SLA compliance and accurate documentation. Performed vulnerability assessments using Tenable Nessus and coordinated remediation with infrastructure teams. Worked with Active Directory administrators to disable compromised user accounts and reset credentials. Coordinated with firewall and network teams to block malicious IP addresses and implement security controls. Prepared daily, weekly and monthly SOC reports highlighting incident trends and security posture. Escalated high-severity incidents to Tier-2 analysts with detailed investigation findings and recommended actions. Participated in client security review meetings and supported continuous improvement of SOC operations.
Education
B.Tech - Jawaharlal Nehru Technological University
- 2017 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Need Sponsorship
Relocation
Open to Relocation
Skills (31)
Click a skill to find developers with the same skill