About
Cybersecurity Analyst with 3 years of experience in Security Operations Center (SOC), SIEM monitoring, threat detection, incident response, vulnerability management, and security monitoring across Windows, Linux, Active Directory, VMware ESXi, network, and AWS cloud environments. Hands-on experience with IBM QRadar SIEM, Rapid7 InsightIDR, Microsoft Sentinel, CrowdStrike Falcon EDR, IDS/IPS, firewall monitoring, AWS CloudTrail, and CloudWatch. Skilled in log analysis, malware investigation, MITRE ATT&CK-based detection engineering, Python/Bash automation, compliance with ISO 27001 and PCI DSS, and collaborating with cross-functional teams to strengthen enterprise security posture.
Skills & Expertise (49)
Work Experience
Associate Cybersecurity Consultant
ControlCase International PVT. LTD
Oct 2023 - Present
Monitored and investigated 1,000+ security events per month using IBM QRadar SIEM, Rapid7 InsightIDR, Microsoft Sentinel, and CrowdStrike Falcon across Windows, Linux, Active Directory, VMware ESXi, databases, firewalls, and AWS environments, improving threat detection efficiency by 30%. Performed real-time security monitoring, alert triage, incident validation, and threat detection by investigating brute-force attacks, malware, ransomware indicators, phishing attempts, privilege escalation, insider threats, and suspicious authentication activities. Analyzed Windows, Linux, application, firewall, IDS/IPS, endpoint, and cloud logs to identify Indicators of Compromise (IOCs), correlate security events, and support rapid incident response. Integrated Windows Servers, Linux Servers, Active Directory, Cisco Switches, pfSense Firewalls, databases, AWS CloudTrail, and CloudWatch log sources into IBM QRadar, increasing centralized security visibility by 35%. Conducted vulnerability assessments by validating security findings, prioritizing remediation based on business risk, and coordinating with infrastructure teams to resolve critical vulnerabilities within SLA timelines. Investigated CrowdStrike Falcon EDR detections involving malware execution, suspicious PowerShell activity, unauthorized processes, and endpoint compromise while supporting containment and recovery activities. Built and optimized IBM QRadar CRE correlation rules, custom parsers, routing rules, dashboards, and AQL searches, reducing false-positive alerts by 25% and improving detection quality. Supported firewall, IDS/IPS, VPN, and network security monitoring by analyzing TCP/IP traffic, DNS, HTTP/HTTPS events, and authentication logs to detect unauthorized access and network-based attacks. Developed Python and Bash automation scripts for SIEM alert enrichment, log retrieval, health monitoring, and repetitive SOC operational tasks, reducing manual effort by 40%. Prepared incident reports, root cause analysis documents, vulnerability assessment reports, security dashboards, and executive summaries while maintaining complete investigation documentation. Supported compliance initiatives aligned with ISO 27001, PCI DSS, NIST Cybersecurity Framework, and MITRE ATT&CK by maintaining audit evidence, security documentation, and operational records. Collaborated with 5+ global stakeholders across cloud, infrastructure, and application teams to investigate security incidents, validate remediation activities, and strengthen enterprise security controls. Tracked emerging cyber threats, attack techniques, vulnerabilities, and threat intelligence to continuously improve detection logic, security monitoring, and SOC response capabilities.
Intern
Tata Consultancy Services
Feb 2023 - Jul 2023
Completed practical cybersecurity training covering Linux administration, secure application development, SIEM operations, networking, and incident response. Designed and implemented a CAPTCHA-based web application security solution to mitigate automated attacks through secure coding practices.
Education
MSc. in Forensic Science - Digital and Cyber Forensics - Government Institute of Forensic Science
2021 - 2023 · Afghanistan
BSc. in Forensic Science - Government Institute of Forensic Science
2018 - 2021 · Afghanistan
Certifications
CompTIA Cybersecurity Analyst CySA+ (CS0-003)
· 2026
AWS Accredited Cloud Practitioner CLF C02
· 2026
CISCO Certified Network Associate 200 301
· 2022
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Citizen
Relocation
Open to Relocation
Skills (49)
Click a skill to find developers with the same skill