About
SOC Analyst with 2.3 Years of experience in IT, with security operations including Incident Management, Endpoint security and logs analysis through SIEM. Experience on working in 24x7 operations of SOC team, offering log monitoring, and security information management.
Skills & Expertise (20)
Work Experience
SOC Analyst
Programmr Technologies
Oct 2023 - Present
Monitoring the incoming security alerts in SIEM tools like QRadar, ArcSight, Azure Sentinel. Working in the Offshore SOC team. Monitoring of SOC events, detecting and preventing the Intrusion attempts. Collecting the log of all the network devices and analysing the logs to find suspicious activities. Investigate the security logs, mitigation strategies and Responsible for preparing generic security incident reports. Handling Alerts from multiple Security Log sources such as Proxy, Anti-Virus and EDR. Deep dive Investigation through Sentinel One EDR. Monitoring, analyzing and responding to infrastructure threats and vulnerabilities. Phishing and Spam Email Analysis. Investigate the security logs, mitigation strategies and responsible for preparing generic security incident reports. Responsible for preparing the root cause analysis reports based on the analysis. Analyzing daily, weekly and monthly reports. Creating case for the suspicious issue and forwarding it to Onsite SOC team for further investigation. Website Anti-Malware and Defacement monitoring and real-time alerting based on anomalies detected. Troubleshooting SIEM dashboard issues when there are no reports getting generated or no data available. Analyzing daily, weekly and monthly reports. Monitoring of SOC events, detecting preventing the Intrusion attempts. Investigating the events based on particular criteria by creating an Active Channel, Handling the failed login issues from the different systems. Handling the different issues like Phishing, Spam and Malicious email. Working on security related threats and Incidents. Investigating security violations, attempts to gain unauthorized access, virus infections, etc. Coordinate responses to security incidents in a timely manner. Work with various teams across the organization to improve security posture.
Education
MCA - VSM College
- 2021 · Afghanistan
Certifications
Certified Information Systems Security Professional (CISSP)
(ISC)² · 2024