About
Security Analyst with 4.5+ years of success in investigating security-related breaches, installing data encryption, and implementing incident response/risk assessment strategies to avert unauthorized access. Proven ability to understand and follow incident response procedures in fast-paced environments. Proficient at training staff on alerting customers to possible malicious activity, resolving priority cases, and creating reports that enable experts to modify security policies.
Skills & Expertise (55)
Work Experience
Associate Security Engineer
EsecForte Technologies
Nov 2023 - May 2024
Supported web and mobile application security testing aligned with OWASP standards. Conducted application vulnerability scans using AppScan and WebInspect. Monitored and tracked remediation progress and provided reports to management. Assisted in risk assessments and threat modeling activities. Worked with Splunk SIEM to monitor, correlate, and analyze application security events.
Soc Analyst
TCS
May 2024 - Present
Implement and manage centralized log collection, parsing, and correlation in Splunk Enterprise Security. Develop, fine-tune, and optimize correlation rules to improve incident detection and reduce false positives. Administer and monitor Microsoft Defender ATP and CrowdStrike Falcon agents across Windows and Linux systems. Perform host isolation, threat analysis, and containment using EDR tools. Prepare endpoint compliance reports and initiate remediation processes wherever required. Manage Office 365 Email Security (Safe Links, Safe Attachments, and DLP rules). Investigate phishing emails, escalate verified threats, and provide user awareness feedback. Collaborate with internal teams for threat remediation and incident closure.
Security Analyst
Wipro
Jun 2021 - Oct 2023
Monitored and investigated alerts generated from CrowdStrike Falcon, Symantec AV, and MCAS. Created custom detection rules in Azure Sentinel using KQL. Performed phishing and malware email analysis using Office 365 Defender and sandbox verdicts. Conducted forensic investigations to identify IoCs and attack vectors. Handled user access and sign-in anomalies in Azure AD (interactive/non-interactive logins). Applied MITRE ATT&CK framework and Diamond Model methodologies for threat analysis. Utilized ServiceNow and JIRA for incident management and documentation.
Education
Bachelor of Computer Science and Education - ISBM University
2019 - 2021 · Afghanistan