About
Security Operations Center (SOC) Analyst with 2+ years of experience protecting enterprise environments through realtime monitoring, incident response, threat hunting, and SIEM engineering. Proven record of reducing false positives by 25%, accelerating incident containment, and strengthening detection. Hands-on expertise with Splunk and Enterprise Security, CrowdStrike EDR, Nessus Vulnerability Management and MITRE ATT&CK.
Skills & Expertise (48)
Work Experience
Operations Associate (SOC)
Lancesoft India Private Limited
May 2024 - Present
Working in a 24x7 Security Operations Center. Monitoring the customer network using Splunk SIEM. Act as first level support for all Security Issues. Analyzing Realtime security incidents and checking whether its true positive or false positive. Raising true positive incidents to the respective team for further action. Creating tickets on service now and assigning it to the respective team and taking the follow-up until closure. Escalating the security incidents based on the client’s SLA and providing meaningful information related to security incidents by doing in-depth analysis of event payload, providing recommendations regarding security incidents mitigation which in turn makes the customer business safe and secure. Contacting the customers directly in case of high priority incidents and helping the customer in the process of mitigating the attacks. Work closely with business units ensure that they know what and how to feed data into the SIEM. Good knowledge of Splunk Distributed Cluster Architecture. Detail knowledge of the working functionality of various components of Splunk such as Indexer, Search head, Heavy forwarder, deployment server etc. Experience in onboarding of data sources with Splunk such as Windows, Linux, Fortinet Firewall etc. Installing Splunk apps and Addon on the Splunk. Experience in installation of Universal forwarder on the servers for logs collection. Responsible for upgrading the Forwarders to the newer versions. Doing the troubleshooting in case any device is not reporting to the Splunk. Knowledge of Creating dashboard, Reports in Splunk. Knowledge and experience in creating Correlation Searches/Rules in Splunk. Working experience searching and Reporting in Splunk having good SPL knowledge.
Education
B.Tech - Kamala Institute of Technology and Science
- 2023 · Afghanistan
Diploma - Government Polytechnic Husnabad
- 2020 · Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Citizen
Relocation
Open to Relocation
Skills (48)
Click a skill to find developers with the same skill