Back to Developers
ramprasad r

ramprasad r

SOC Analyst

4+ yrs exp 88 ยท Excellent

About

Skilled SOC Analyst with 3.8 years of hands-on experience in cybersecurity, specializing primarily in MSSP projects. Proficient in 24x7 SOC operations, providing round-the-clock log monitoring and security information management. Good knowledge on networking concepts including OSI layers, Subnet, TCP/IP, Ports, DNS, DHCP. Analyzing real-time security incidents and checking whether it's true positive or false positive. Analyzed 20-35 security incident data from endpoint, EDR, XDR, Firewalls, IDS, & IPS daily. Proactively monitored & investigated 25+ weekly security incidents & promptly raised tickets for timely client resolution. Consistently met SLAs for alert triage, investigation, and escalation with efficiency and precision. Strong knowledge on Incident management life cycle. Worked closely with Vulnerability Management & designated incident response team, fostering collaboration & ensuring a coordinated approach to security incidents. Collecting, analyzing, and interpreting threat intelligence data to identify potential cybersecurity threats. Leveraging threat intelligence feeds (IOCs) and conducting proactive threat hunting to identify and mitigate potential security threats. Conducting thorough using Qualys vulnerability assessments to identify, prioritize, and mitigate security risks. Performed in-depth investigations into phishing, malware, web attacks, and network-related alerts, utilizing SIEM solutions, EDR solution Email gateway and open-source threat intelligence tools such as Censys, Shodan, Virus Total, and Abuse IPDB - Having good knowledge on MITRE ATT&CK Framework and Cyber kill chain. Strong understanding of Proof point email security solutions, defending against advanced email threats, including phishing and malware attacks, thereby minimizing the risk of successful email-based breaches. Conducted thorough analysis of email security logs and alerts within Proof point TAP, promptly identifying and mitigating suspicious activities and unauthorized email access attempts in real-time. Analyzed CrowdStrike Falcon platform alerts to identify and mitigate potential security threats effectively. Utilizing the UEBA (LogRhythm, Rapid7) platform to detect anomalous user activities and insider threats. Conducted security assessments identifying vulnerabilities and recommending remediation measures to mitigate risks effectively.

Skills & Expertise (27)

Elastic Advanced
8.3/10
2
Years Exp
Splunk Advanced
8.3/10
2
Years Exp
Microsoft Defender Advanced
8.0/10
2
Years Exp
CrowdStrike Advanced
8.0/10
2
Years Exp
AWS Intermediate
7.5/10
1
Years Exp
GCP Intermediate
7.0/10
1
Years Exp
Azure Intermediate
7.0/10
1
Years Exp
Windows Intermediate
7.0/10
4
Years Exp
LINUX Intermediate
7.0/10
4
Years Exp
ServiceNow Intermediate
6.5/10
1
Years Exp
Ubuntu Intermediate
6.5/10
4
Years Exp
Trend Micro Microsoft Outlook Zendesk Microsoft Word Microsoft Excel Microsoft PowerPoint ProofPoint AlienVault OTX CISCO Talos VirusTotal MISP Rapid7 LogRhythm Forcepoint DLP Symantec DLP IBM QRadar

Work Experience

SOC Analyst

PROFICI

Oct 2023 - Present

Monitoring real-time security incidents using SIEM tools like Splunk, Elastic and EDR solutions such as CrowdStrike Falcon and Microsoft Defender. Investigating security alerts, analyzing threats, creating incident tickets, and escalating critical cases to onsite SOC teams for further investigation. Assessing the impact of security alerts and traffic anomalies to identify malicious activities and coordinating with customers and internal teams for mitigation actions. Performing threat analysis to determine impact, scope, and recovery actions using various security tools and technologies. Collaborating with internal teams and customer incident response teams during security investigations and response activities. Implementing SIEM fine-tuning and whitelisting strategies to reduce noise and minimize false positive alerts. Writing correlation rules in Elastic using EQL and developing interactive dashboards for effective security monitoring. Preparing daily, weekly, and monthly SOC reports based on customer requirements. Monitoring device health and reporting status for systems under SOC monitoring. Managing incident tracking, documentation, and resolution using ticketing tools like Zoho and ServiceNow. Managing cloud security monitoring and incident investigation for cloud-based environments, including AWS-related security alerts. Identifying potential threats, leaked data, vulnerabilities, and assessing organizational attack surfaces to improve overall security posture. Maintaining asset inventory for multiple clients and generating client-specific security reports on a regular basis. Fine-tuned 20+ SIEM rules, reducing false positives by up to 7% and improving SOC monitoring efficiency. Performing daily SIEM health checks and identifying attacks based on signatures and alert patterns. Keeping up to date with the latest cybersecurity threats, attack techniques, trends, and security technologies.

SOC Analyst

AR Softcon Pvt Ltd.

May 2022 - Sep 2023

Education

B.COM - Maharishi University of Information Technology (MUIT)

- 2020 ยท Afghanistan

Certifications

No certifications added yet

Interested in this developer?

Profile Score Breakdown

๐Ÿ“ท Photo 10/10
๐Ÿ“„ Resume 10/10
๐Ÿ’ผ Job Title 10/10
โœ๏ธ Bio 10/10
๐Ÿ› ๏ธ Skills 20/20
๐ŸŽ“ Education 10/10
โฑ๏ธ Experience 13/15
๐Ÿ’ฐ Rate 0/5
๐Ÿ† Certs 0/5
โœ… Verified 5/5
Total Score 88/100

Profile Overview

Member sinceJul 2026

Availability Details

Visa Status

Need Sponsorship

Relocation

Open to Relocation