About
Information Security Analyst with 3 years of experience in 24x7 Security Operations Center (SOC) environments, specializing in SIEM monitoring, incident response, threat detection, log analysis, phishing investigations, malware analysis, and vulnerability management. Experienced with Splunk, IBM QRadar, CrowdStrike Falcon, Microsoft Defender, ServiceNow, and Qualys. Strong understanding of MITRE ATT&CK, incident handling, and security monitoring with a focus on proactive threat detection and continuous security improvement.
Skills & Expertise (36)
Work Experience
Information Security Analyst
Tata Consultancy Services (TCS)
Aug 2023 - Present
Working in Security Operation Center (24x7), monitoring SOC events. Monitoring real-time events using SIEM tools like Splunk, IBM Qradar. Security Operation centers (SOC) environment (log analysis, event analysis, incident investigation, reporting). Responding to various security alerts, incidents for various clients. Assisted in fine-tuning SIEM correlation rules and alert thresholds to reduce false positives and improve detection accuracy. Experience in performing log analysis, Phishing email analysis, Malware Analysis and other incident analysis, analyzing the crucial alerts on an immediate basis. Monitor and analyze security alerts from various sources, including Microsoft Azure, Zscaler. Collecting the logs from network devices and analyze the logs to find the suspicious activities. Analyzed blocked and suspicious URLs to identify legitimate or malicious activity. Investigated suspicious URLs and performed incident response actions such as blocking, quarantining, and user awareness. Performed root cause analysis for confirmed true positive incidents and documented findings. Monitored and analyzed URLs using security tools to detect phishing, malware, and malicious activity. Maintained detailed incident documentation, investigation notes, evidence, and remediation recommendations in ServiceNow. Conducted vulnerability scans on URLs, portals, and software using tools like Nessus, Qualys, and to identify security weaknesses. Presented website and URL vulnerability reports with security recommendations to executive committees. Monitored emerging cyber threats, updated security scanning processes, and recommended security enhancements. Technical knowledge on security tools (Proxy, WAF, Anti-virus/malware, IDS/IPS, Firewall, DNS, DHCP, vulnerability, etc.) and infrastructure (Network, OS, Database). Contacting customers directly in case of high priority incidents and assisting customer in the process of mitigating the attacks. Created and maintained SIEM dashboards, scheduled reports, and security metrics for operational visibility. Ability to collaborate and communicate effectively and respectfully with both business-oriented.
Education
Bachelor of Engineering (BE), Electronics and Telecommunications - D Y Patil College of Engineering & Technology
- 2022 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Citizen
Relocation
Open to Relocation
Skills (36)
Click a skill to find developers with the same skill