About
As a detail-driven Security Analyst with 2 years of experience in SOC operations, I excel in SIEM monitoring, endpoint security, and incident investigation, leveraging my expertise to drive real-time threat detection and response. With hands-on experience in EDR tools like CrowdStrike Falcon and email security solutions like Mimecast and Netskope, I am well-versed in analyzing security alerts and coordinating incident response efforts. My strong foundation in security monitoring and analysis enables me to effectively triage potential incidents and support continuous SOC operations.
Skills & Expertise (24)
Work Experience
Associate - Engineer
ISSQUARED INDIA
Apr 2024 - Present
Monitored and analyzed security alerts using Securonix SIEM, ensuring timely detection and response to potential threats and identifying true security incidents. Investigated security events from firewalls, endpoints, servers, and IDS/IPS solutions to accurately distinguish between false positives and actionable security incidents. Provided continuous 24ร7 SOC operational monitoring, maintaining vigilance over enterprise security infrastructure and following predefined playbooks for consistent incident response. Supported DLP operations using Digital Guardian, Mimecast, and Netskope by monitoring alerts, reviewing outbound communications, and reporting potential data exposure risks. Analyzed spam and phishing emails to identify malicious indicators and coordinated with asset owners to provide remediation guidance and security awareness recommendations. Monitored inbound and outbound email traffic using Mimecast to identify data leakage risks and malicious communication attempts. Monitored cloud application activities and analyzed inbound/outbound data transfers and web uploads using Netskope to prevent sensitive data exposure. Monitored and investigated CrowdStrike EDR alerts, analyzing endpoint detections and coordinating response actions. Performed incident response actions including host isolation, process termination, and IOC deployment. Managed endpoint security policies, RTR, USB/removable media controls, and endpoint sensor health monitoring. Conducted threat hunting and forensic investigations for critical incidents. Onboarded SIEM data sources by configuring log ingestion, validating parsing, and ensuring accurate event visibility. Developed and fine-tuned detection policies and correlation rules to improve alert accuracy and reduce false positives. Troubleshot log ingestion, connectivity, and agent communication issues to maintain uninterrupted monitoring. Supported log collection setup and diagnostics across Windows and Linux systems, ensuring reliable log forwarding. Configured and troubleshot NXLog (Windows) and rsyslog (Linux) to ensure reliable log forwarding and SIEM log ingestion. Basic knowledge of Python scripting and hands-on experience with Linux command-line tools for system administration and troubleshooting.
Education
Bachelor of Technology - Vardhaman College of Engineering
- 2022 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Citizen
Relocation
Open to Relocation
Skills (24)
Click a skill to find developers with the same skill