About
Cybersecurity Analyst with 3+ years of IT experience, including 2+ years of hands-on SOC experience in security monitoring, incident investigation and threat detection. Experienced in Microsoft Sentinel, Microsoft Defender XDR, Microsoft Entra ID and KQL, with hands-on experience investigating identity, endpoint, phishing, malware and authentication-related threats. Skilled in threat hunting, detection tuning, incident response, quality auditing, RCA documentation and stakeholder communication. Targeting opportunities in IAM/Identity Security, Microsoft Security, DLP/Email Security and Cybersecurity Engineering.
Skills & Expertise (25)
Work Experience
SOC Analyst (L1 & L2)
Zensar Technologies
Jun 2024 - Present
Perform L2 investigation and triage of security incidents using Microsoft Sentinel and Microsoft Defender XDR, covering identity, endpoint, phishing, malware and authentication-related threats. Investigated 1,500+ security incidents involving phishing, malware, identity compromise, credential misuse and privilege-related activities. Own L2 incident investigations from initial analysis through resolution, coordinate with resolver teams, follow up on open incidents and support L1 analysts with investigation guidance. Perform quality audits of L1 security incidents to identify gaps in investigation, documentation and remediation; conduct one-on-one feedback sessions with L1 analysts to improve investigation quality. Analyze Microsoft Entra ID sign-in and authentication activity to identify suspicious login patterns, account compromise and identity-based threats. Develop and execute KQL queries for security investigations, threat hunting and detection analysis. Perform threat hunting using Microsoft Sentinel and Defender XDR to identify suspicious activities and advanced threats. Tune Sentinel analytics rules and use cases to reduce false positives and improve detection effectiveness. Investigate phishing emails, malicious URLs, malware and endpoint security incidents and coordinate remediation with resolver teams. Prepare incident reports, RCA documentation and weekly security reports for stakeholders/clients; mentor junior analysts. Collaborate with IT, network, cloud and application teams during security investigations and remediation.
Trainee Programmer
TurboModus Private Limited
Feb 2023 - Sep 2023
Developed web applications using HTML, CSS, JavaScript, VB.NET, C# and SQL. Managed SQL databases and implemented access-control mechanisms to maintain data integrity. Gained foundational exposure to application security and backend security practices.
Education
B.Tech / B.E. — Electronics & Communication Engineering - Megha Institute of Engineering and Technology for Women (MIETW)
2018 - 2022 · Afghanistan
Diploma — Electronics & Communication
- 2018 · Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (25)
Click a skill to find developers with the same skill