Sohail
Security Analyst
About
IT Experience overall 6 years and Security Analyst role with 3 years of experience in enterprise Security Operations Center (SOC) environments supporting 24/7 cybersecurity monitoring and incident response. Strong expertise in SIEM monitoring, detection engineering support, advanced log analysis, endpoint detection and response (EDR), firewall security monitoring, cloud security operations, and vulnerability management. Experienced in handling high-severity (P1/P2) security incidents across network, endpoint, server, email, and cloud environments. Skilled in MITRE ATT&CK mapping, Cyber Kill Chain analysis, root cause analysis, digital evidence collection, and compliance support aligned with NIST and ISO 27001 frameworks.
Skills & Expertise (45)
Work Experience
Security Analyst
Wipro
Jul 2023 - Present
Lead investigation and response of high and critical (P1/P2) cybersecurity incidents across enterprise infrastructure including network, endpoint, server, cloud, and email environments. Perform advanced log analysis and event correlation using Splunk, IBM QRadar, Microsoft Sentinel, and LogRhythm. Detect and investigate security threats including lateral movement, privilege escalation, ransomware indicators, brute force attacks, insider threats, command-and-control (C2) communication, and suspicious outbound traffic. Conduct detailed EDR investigations using CrowdStrike, Symantec, and McAfee by analyzing process trees, command-line execution, registry changes, scheduled tasks, persistence techniques, and abnormal network connections. Map incidents and detection use cases to MITRE ATT&CK techniques to improve monitoring coverage and visibility. Tune SIEM correlation rules to reduce false positives and improve alert accuracy. Perform log onboarding activities including syslog configuration, parsing validation, field extraction, normalization, and event categorization. Monitor SIEM platform performance including log ingestion health, event latency, storage utilization, and data retention compliance. Execute containment actions including endpoint isolation, firewall IP/domain blocking, account lockout, access revocation, and MFA enforcement. Conduct root cause analysis (RCA) to identify attack vector, exploited vulnerability, impacted assets, and business risk exposure. Perform retrospective log analysis after incidents to identify detection gaps and strengthen monitoring rules. Monitored and investigated DLP alerts (data exfiltration, policy violations, sensitive data movement). Analyzed user activity, file transfers, email attachments, and endpoint actions for data leakage risks. Investigate phishing campaigns including email header analysis, spoofing validation, URL detonation, and attachment sandboxing. Analyze authentication logs to detect password spraying, credential stuffing, abnormal login patterns, and suspicious geo-location activity. Support vulnerability remediation validation by reviewing Nessus and Qualys scan findings and verifying patch implementation. Collaborate with VAPT teams to validate exploitability and remediation closure. Led shift handovers, incident prioritization, workload distribution, and SLA governance. Document incident findings in ServiceNow ensuring SLA compliance and audit traceability. Worked with Microsoft Sentinel & Logic Apps to support alert automation and response workflows. Assisted in developing playbooks for automated actions such as alert enrichment, ticket creation, and notification triggers. Coordinated with OEM vendors (Microsoft, CrowdStrike, SIEM providers) for issue resolution, threat intelligence, and advanced investigations. Participated in governance meetings, incident review boards, and lessons learned sessions. Provide SOC operational evidence aligned with ISO 27001 and NIST compliance audits.
IT Desktop Support Engineer
Cadential Technologies Private Limited
May 2020 - Jun 2023
Installed, configured, and maintained servers, desktops, laptops, and mobile devices. Managed user accounts, groups, and permissions using Active Directory. Provided technical support for hardware, software, and network-related issues. Monitored and maintained network devices such as routers, switches, and firewalls. Ensured regular system backups and tested disaster recovery plans. Applied software updates, patches, and security fixes to all client systems. Supported Microsoft 365 services including Exchange Online, Teams, and SharePoint. Implemented antivirus and endpoint security solutions to protect client data. Managed virtualization platforms like VMware and Hyper-V for efficient resource use. Created and updated IT documentation, including network diagrams and SOPs. Supported VoIP phone systems and business communication tools. Coordinated with vendors for hardware/software procurement and technical support. Provided remote and on-site client support to ensure minimal downtime.
Education
Bachelor of Technology - Anwar Ul-Uloom College of Engineering, JNTU University
- ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (45)
Click a skill to find developers with the same skill