Tushar Patil
SOC Analyst L1
About
SOC Analyst L1 with around 3.3 years of experience in Security Operations, Security Monitoring, Incident Analysis, and Phishing Email Analysis within a 24ร7 SOC environment. Experienced in monitoring and investigating security alerts, performing initial triage, validating incidents, escalating confirmed threats as per the escalation matrix, and ensuring SLA compliance. Hands-on experience with Splunk, QRadar, CrowdStrike Falcon, Freshservice, Proofpoint, sandboxing solutions, and threat intelligence platforms. Skilled in analyzing Windows security events, authentication logs, endpoint alerts, phishing emails, malicious URLs, IP addresses, file hashes, and domains to identify potential security threats. Familiar with SIEM, EDR, MITRE ATT&CK Framework, Active Directory, Azure AD, Windows Event Logs, and basic incident response processes. Experience in performing daily SIEM health checks, creating and updating incident tickets, preparing daily, weekly, and monthly SOC reports, and communicating security incidents to clients. Strong understanding of cybersecurity fundamentals, including malware, phishing, brute-force attacks, ransomware, IOC analysis, and log analysis, with a continuous learning mindset and commitment to improving security operations.
Skills & Expertise (35)
Work Experience
Security Analyst L1
Accenture
May 2023 - Present
Monitor security events using SIEM and analyze system logs and network traffic to detect malicious activities. Collect, manage, and analyze logs from multiple sources to ensure comprehensive security monitoring. Investigate security logs, recommend mitigation strategies, and prepare security incident reports. Monitor and investigate alerts from multiple security solutions, including Proxy, Firewalls, and EDR. Create and maintain daily, weekly, and monthly operational reports. Monitor and analyze security events and alerts from multiple sources, including network devices, IDS/IPS, firewalls, system logs, and databases. Raise incidents with the relevant teams, respond to security incidents and service requests, gather additional information, and escalate issues when required. Act as the first-level support for security incidents and operational security issues. Perform real-time security monitoring, investigation, analysis, and reporting. Track pending incident tickets and follow up until closure while ensuring SLA compliance. Prepare weekly and monthly customer review reports. Perform daily operational status checks and validate security monitoring activities. Work in a 24ร7 Security Operations Center (SOC) environment. Monitor and analyze real-time security alerts to determine whether they are true positives or false positives. Perform log analysis and investigate critical security alerts on a priority basis. Analyze phishing emails, spam emails, email headers, attachments, URLs, IP addresses, and domains to identify malicious activity. Investigate email security threats and implement appropriate remediation by blocking malicious URLs at the Proxy, blocking malicious IP addresses at the Firewall, and blocking malicious senders and domains in the Email Security Gateway.
Education
Bachelor of Technology - Shivaji University, Kolhapur
- 2022 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (35)
Click a skill to find developers with the same skill