About
Cybersecurity Analyst with 2.8+ years of hands-on experience in 24×7 SOC operations, specializing in SIEM monitoring, incident investigation, endpoint analysis, and threat detection. Strong expertise in IBM QRadar, Microsoft Defender, CrowdStrike, and Cortex XDR. Experienced in alert triage, event correlation, MITRE ATT&CK-based analysis, and end-to-end incident lifecycle handling. Demonstrated ability to manage high alert volumes while maintaining SLA compliance and improving detection quality.
Skills & Expertise (49)
Work Experience
Security Consultant (SOC)
Forvis Mazars LLP
Nov 2024 - Present
Perform 24×7 monitoring and investigation of security events using IBM QRadar and EDR platforms. Handle 90-100 alerts per shift, ensuring proper triage, validation, and escalation as per SOP. Correlate SIEM logs with endpoint telemetry to validate suspicious PowerShell execution, abnormal logins, and outbound connections. Investigate phishing emails through header analysis, sandbox review, and IOC extraction. Map incidents to MITRE ATT&CK framework to improve detection visibility. Support false-positive reduction by assisting in correlation rule tuning and threshold adjustments. Maintain structured documentation and ensure SLA/KPI compliance.
Security Operations Center Analyst
Hala Infosec Private Limited
Jun 2023 - Oct 2024
Monitored and analyzed alerts across endpoints, firewalls, IDS/IPS, proxy logs, and email security tools. Investigated ~150+ incidents per month, including lateral movement indicators and potential data exfiltration patterns. Conducted IOC collection, enrichment, and validation using threat intelligence feeds. Assisted in onboarding log sources and supporting detection rule improvements under senior guidance. Contributed to MTTR optimization through improved triage workflow and standardized investigation checklists. Supported containment actions including endpoint isolation and account disablement during confirmed incidents.
Education
Bachelor of Technology in Computer Science Engineering – Cybersecurity - Gandhi Institute of Technology and Management
- · Afghanistan