About
Microsoft SC-200 Certified SOC Analyst with 2 years of experience in Security Operations Centre environments. Handles security alert monitoring and investigation using ArcSight SIEM, managing end-to-end incident lifecycle from detection through containment, remediation, and post-incident reporting. Maintains strong SLA compliance for high and critical incidents through consistent alert investigation, documentation, and cross-team coordination. Skilled in threat detection, IOC correlation, and MITRE ATT&CK-based adversary mapping across enterprise environments. Combines SOC operational discipline with a strong analytical foundation in electrical and embedded systems engineering.
Skills & Expertise (28)
Work Experience
SOC Analyst
HCLTech
Jun 2025 - Present
Monitor and triage security alerts daily using ArcSight ESM — analysing event correlation rules, filter logic, and active channels to detect threats across endpoints, identities, email, and cloud workloads. Perform L1 alert triage — classify severity, assign priority, and initiate response workflows; consistently meet 1–2 hour SLA targets for high and critical incidents across the WASL environment. Investigate security events across Windows Event logs, Azure AD sign-in logs, and network telemetry; correlate Indicators of Compromise (IOCs) and identify lateral movement, privilege escalation, and persistence patterns. Manage end-to-end incident lifecycle — detection, containment, remediation, recovery, and post-incident reporting with root cause analysis documented in ServiceNow, escalating complex or high-severity cases to senior analysts when necessary. Map adversary TTPs to the MITRE ATT&CK framework; coordinate containment actions including device isolation, account disabling, and conditional access policy enforcement in collaboration with endpoint and identity teams. Support vulnerability assessment processes by identifying exposed assets from scan results and coordinating with IT teams to ensure timely patching and remediation of identified vulnerabilities. Contribute to the development and maintenance of security documentation, investigation runbooks, and incident response procedures. Produce daily and weekly SOC operational reports covering incident status, SLA compliance, alert volume trends, and threat pattern summaries for WASL client stakeholders. Stay current with emerging threats, attacker techniques, and SOC tooling through continuous learning, self-driven research, and Microsoft SC-200 certification training.
SOC Intern
HCLTech
Jan 2025 - Jun 2025
Assisted the SOC team with monitoring security alerts and event logs, gaining hands-on exposure to alert triage workflows, escalation procedures, and SIEM-based investigation practices. Learned foundational SIEM concepts, security documentation standards, and incident reporting practices under senior analyst guidance, building a strong base for the SOC Analyst role that followed.
Intern
TS TRANSCO
May 2023 - Jul 2023
Studied power system protection schemes; assisted in testing and troubleshooting protective relay devices; collaborated with engineers on innovative protection solutions.
Intern
PLNS (Suryamitra) Pvt. Ltd.
Feb 2021 - Jul 2021
Contributed to solar panel system design at a renewable energy firm; gained practical experience in photovoltaic systems and sustainable energy technology.
Education
B.E., Electrical & Electronics Engineering - Stanley College of Engineering & Technology for Women
- 2024 · Afghanistan
Diploma, Electrical & Electronics Engineering - Government Polytechnic College
- 2021 · Afghanistan
SSC (10th Standard) - Z.P.G.H. School
- 2018 · Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Need Sponsorship
Relocation
Open to Relocation
Skills (28)
Click a skill to find developers with the same skill