About
Splunk Administrator and SOC Analyst (official designation: Cyber Security Associate) with hands-on expertise across both SIEM administration and security operations. Skilled in enterprise-scale Splunk deployments (3,000+ forwarders, 150+ users, multi-TB daily indexing volume), SPL, Splunk Enterprise Security (ES) v10.4.2, indexer/search head clustering, and deployment server management, alongside real-time SOC monitoring and incident triage using ArcSight. Backed by a strong foundation in networking and security fundamentals (CompTIA Network+, Security+).
Skills & Expertise (36)
Work Experience
Splunk Administration
Kotak Mahindra Bank
Jul 2024 - Present
Install, configure, and maintain Splunk Enterprise across Production and DR, including indexer clustering, search head clustering, and deployment server management. Manage 3,000+ Universal Forwarders with log forwarding via Syslog, sustaining 99.9% uptime and fault tolerance across Production and DR. Manage data inputs, log onboarding, parsing, and indexing; troubleshoot log ingestion stoppages. Write and optimize SPL queries to build dashboards and reports; administer Splunk Enterprise Security (ES) v10.4.2 for correlation searches, notable events, and use-case tuning. Deploy and manage Technology Add-ons (TAs) and custom apps across the environment via the deployment server. Administer RBAC for 150+ users, enforcing least-privilege access and security best practices. Monitor system resources, license usage, and daily indexing volume (multi-TB scale, thousands of GB/day); perform regular Splunk health checks. Monitor real-time SIEM alerts and fine-tune use cases, reducing false positives by 30%. Investigate log ingestion failures, deliver RCA reports, and coordinate with clients to maintain SIEM data availability.
Cyber Security Associate
Sattrix Information Security Ltd.
Feb 2024 - Present
Install, configure, and maintain Splunk Enterprise across Production and DR, including indexer clustering, search head clustering, and deployment server management. Manage 3,000+ Universal Forwarders with log forwarding via Syslog, sustaining 99.9% uptime and fault tolerance across Production and DR. Manage data inputs, log onboarding, parsing, and indexing; troubleshoot log ingestion stoppages. Write and optimize SPL queries to build dashboards and reports; administer Splunk Enterprise Security (ES) v10.4.2 for correlation searches, notable events, and use-case tuning. Deploy and manage Technology Add-ons (TAs) and custom apps across the environment via the deployment server. Administer RBAC for 150+ users, enforcing least-privilege access and security best practices. Monitor system resources, license usage, and daily indexing volume (multi-TB scale, thousands of GB/day); perform regular Splunk health checks. Monitor real-time SIEM alerts and fine-tune use cases, reducing false positives by 30%. Investigate log ingestion failures, deliver RCA reports, and coordinate with clients to maintain SIEM data availability.
SOC Operations
Sattrix Information Security Ltd.
Feb 2024 - Jul 2024
Monitored and triaged real-time security alerts using ArcSight SIEM, escalating confirmed threats to L2. Investigated phishing, malware, brute-force, and ransomware attacks. Documented security incidents with detailed event analysis, ensuring accurate escalation within SLA timelines. Correlated alerts with threat intelligence feeds and known IOCs to determine incident severity.
Intern โ SOC Analyst
Infopercept Consulting Pvt. Ltd.
Aug 2023 - Jan 2024
Completed cybersecurity training covering networking, security fundamentals, SOC operations, Linux, and Splunk SIEM monitoring, with practical log analysis experience.
Education
Master of Computer Applications - GIET University
2022 - 2024 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Citizen
Relocation
Open to Relocation
Skills (36)
Click a skill to find developers with the same skill