About
Having 7 years 2 months relevant experience in Information Security and currently working as Security Analyst (Security Operation Centre team). Hands on experience on Threat analysis and Security Monitoring and Operation. Experience on SIEM (Security Information and Event Management) tools like Monitoring real-time events using Splunk tool. Expertise in defining resources like Rules, Filters, Dash Boards etc. Strong knowledge on Event Life Cycle and its Phases. Strong knowledge on Incident management life cycle. Good knowledge on networking concepts including OSI layers, subnet, TCP/IP, ports, DNS etc. Good understanding of security solutions like Firewalls (Palo Alto), Anti-virus, IPS, Proxy etc. Preparing daily, weekly and monthly report as per client requirement. Investigating and creating case for the security threats and forwarding it to Onsite SOC team for further investigation and action. Experience on performing log analysis and analyzing the crucial alerts at immediate basis. Filling the Daily health checklist of SIEM. Preparing reports as per client request, Preparing Knowledge base and use cases. Reporting weekly / monthly dashboards to customer. Recognizing attacks based on their signatures. Monitoring and carrying out second level analysis incidents.
Skills & Expertise (30)
Work Experience
Security Analyst
High Spring (Client: Fullsteam)
Sep 2024 - Present
Security Monitoring and Operations (MSSP)
Information Security Analyst 11
TSYS Global payments
Mar 2021 - Feb 2024
Global Security Operations(PCIDSS)
Security Analyst 1
Wipro
Jun 2018 - Mar 2021
Security Monitoring and Operations (MSSP)
Education
B.Tech in BME - BVRIT
- 2018 · Afghanistan