About
Results-driven Information Security Analyst L1 / SOC Analyst with 2.3+ years of experience in 24/7 Security Operations Center (SOC) environments. Proven expertise in SIEM administration, correlation rule development, use-case engineering, and end-to-end incident response across IBM QRadar, Splunk, and Microsoft Sentinel. Skilled in security monitoring, threat hunting, log analysis, phishing and malware investigation, and detection-engineering initiatives that reduce false positives and strengthen enterprise security posture. Adept at cross-functional collaboration, stakeholder reporting, and maintaining SLA-driven SOC operations for enterprise clients.
Skills & Expertise (44)
Work Experience
Information Security Analyst L1 / SOC Analyst / Security Analyst L1
Accenture
Jun 2024 - Present
Monitor and analyze security alerts in real time using Splunk and IBM QRadar, performing incident triage, root-cause investigation, and escalation of critical incidents per SOC standard operating procedures, supporting 2.3+ years of continuous SOC operations. Develop and implement SIEM use cases based on emerging threat scenarios; fine-tune correlation rules and detection logic, reducing false positives/negatives and improving alert fidelity and analyst efficiency. Build and manage QRadar Building Blocks, Reference Sets, active channels, filters, custom queries, correlation rules, and dashboards to strengthen detection coverage across enterprise environments. Perform end-to-end log onboarding and integration of log sources — including IDS/IPS, firewalls, EDR, proxy, and gateway devices — into SIEM platforms; maintain SIEM health, availability, and performance. Conduct log analysis across network, endpoint, and cloud sources to identify attack patterns, suspicious behavior, and indicators of compromise (IOCs), supporting faster mean-time-to-detect (MTTD). Investigate and remediate phishing campaigns by analyzing email headers, attachments, and malicious URLs; coordinate blocking of malicious sources and document findings for stakeholder visibility. Leverage CrowdStrike Falcon and Microsoft Defender EDR platforms to identify, contain, and remediate endpoint threats; apply malware analysis and sandboxing techniques to validate indicators. Support proactive threat hunting initiatives across log sources using advanced SIEM query logic (SPL, KQL, AQL) combined with threat intelligence feeds to uncover advanced persistent threats (APTs). Document use-case logic, rule-tuning activities, and incident timelines; author daily, weekly, and monthly security reports covering alert trends, deny logs, failed logons, AV coverage, and network security posture for stakeholders. Respond to security incidents in accordance with internal cyber incident response procedures, applying digital forensics techniques and preserving evidence integrity as required. Maintain 24/7 SOC operations coverage, complete daily health checklists, and ensure continuous monitoring for targeted phishing campaigns and priority security alerts across client environments. Mentor and onboard new SOC analysts on QRadar/Splunk workflows and escalation procedures, contributing to reduced ramp-up time for the team.
Education
Bachelor of Technology (B.Tech) - MGM College
2020 - 2024 · Afghanistan
Certifications
CEH
Certified Ethical Hacker · 2026
Na
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Citizen
Relocation
Open to Relocation
Skills (44)
Click a skill to find developers with the same skill