ramprasad r
SOC Analyst
About
Skilled SOC Analyst with 3.8 years of hands-on experience in cybersecurity, specializing primarily in MSSP projects. Proficient in 24x7 SOC operations, providing round-the-clock log monitoring and security information management. Good knowledge on networking concepts including OSI layers, Subnet, TCP/IP, Ports, DNS, DHCP. Analyzing real-time security incidents and checking whether it's true positive or false positive. Analyzed 20-35 security incident data from endpoint, EDR, XDR, Firewalls, IDS, & IPS daily. Proactively monitored & investigated 25+ weekly security incidents & promptly raised tickets for timely client resolution. Consistently met SLAs for alert triage, investigation, and escalation with efficiency and precision. Strong knowledge on Incident management life cycle. Worked closely with Vulnerability Management & designated incident response team, fostering collaboration & ensuring a coordinated approach to security incidents. Collecting, analyzing, and interpreting threat intelligence data to identify potential cybersecurity threats. Leveraging threat intelligence feeds (IOCs) and conducting proactive threat hunting to identify and mitigate potential security threats. Conducting thorough using Qualys vulnerability assessments to identify, prioritize, and mitigate security risks. Performed in-depth investigations into phishing, malware, web attacks, and network-related alerts, utilizing SIEM solutions, EDR solution Email gateway and open-source threat intelligence tools such as Censys, Shodan, Virus Total, and Abuse IPDB - Having good knowledge on MITRE ATT&CK Framework and Cyber kill chain. Strong understanding of Proof point email security solutions, defending against advanced email threats, including phishing and malware attacks, thereby minimizing the risk of successful email-based breaches. Conducted thorough analysis of email security logs and alerts within Proof point TAP, promptly identifying and mitigating suspicious activities and unauthorized email access attempts in real-time. Analyzed CrowdStrike Falcon platform alerts to identify and mitigate potential security threats effectively. Utilizing the UEBA (LogRhythm, Rapid7) platform to detect anomalous user activities and insider threats. Conducted security assessments identifying vulnerabilities and recommending remediation measures to mitigate risks effectively.
Skills & Expertise (27)
Work Experience
SOC Analyst
PROFICI
Oct 2023 - Present
Monitoring real-time security incidents using SIEM tools like Splunk, Elastic and EDR solutions such as CrowdStrike Falcon and Microsoft Defender. Investigating security alerts, analyzing threats, creating incident tickets, and escalating critical cases to onsite SOC teams for further investigation. Assessing the impact of security alerts and traffic anomalies to identify malicious activities and coordinating with customers and internal teams for mitigation actions. Performing threat analysis to determine impact, scope, and recovery actions using various security tools and technologies. Collaborating with internal teams and customer incident response teams during security investigations and response activities. Implementing SIEM fine-tuning and whitelisting strategies to reduce noise and minimize false positive alerts. Writing correlation rules in Elastic using EQL and developing interactive dashboards for effective security monitoring. Preparing daily, weekly, and monthly SOC reports based on customer requirements. Monitoring device health and reporting status for systems under SOC monitoring. Managing incident tracking, documentation, and resolution using ticketing tools like Zoho and ServiceNow. Managing cloud security monitoring and incident investigation for cloud-based environments, including AWS-related security alerts. Identifying potential threats, leaked data, vulnerabilities, and assessing organizational attack surfaces to improve overall security posture. Maintaining asset inventory for multiple clients and generating client-specific security reports on a regular basis. Fine-tuned 20+ SIEM rules, reducing false positives by up to 7% and improving SOC monitoring efficiency. Performing daily SIEM health checks and identifying attacks based on signatures and alert patterns. Keeping up to date with the latest cybersecurity threats, attack techniques, trends, and security technologies.
SOC Analyst
AR Softcon Pvt Ltd.
May 2022 - Sep 2023
Education
B.COM - Maharishi University of Information Technology (MUIT)
- 2020 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Need Sponsorship
Relocation
Open to Relocation
Skills (27)
Click a skill to find developers with the same skill