About
SOC Analyst/ Security Engineer with 4 years of hands-on experience in security monitoring, SIEM administration, Endpoint detection and response, and cyber incident investigations. Skilled in IBM QRadar, SentinelOne, CrowdStrike, Web application firewall and experience in offense analysis, log correlation, threat detection, and investigating malware, phishing, and ransomware incidents. Hands-on experience on SOC engineering activities including log source Integrations, rule creations, Event Collector Deployment, Event Processor Deployment and offense analysis.
Skills & Expertise (18)
Work Experience
SOC Analyst
Cloud4C Services Private Limited
Jul 2022 - Present
Monitoring and performing investigations using SIEM by analyzing correlated events, logs, event payloads, asset context, source/destination IPs, and event timelines to validate security threats. Investigated security offenses using event correlation, log analysis, and threat intelligence to identify suspicious activities, prioritized security incidents, incident response activities- detection, triage, and incident response. Performed endpoint investigations using SentinelOne, CrowdStrike to analyze malware infections, ransomware activity, phishing incidents, and suspicious endpoint behaviour. Performed malware analysis and threat triage to identify malicious behaviour and Indicators of Compromise (IOCs) & indicator of Attacks (IOAs). Optimized offense thresholds, correlation rules, and detection logic to reduce alert noise false positives and improve SOC efficiency. Monitored and investigated security events from integrated security technologies, including EDR solutions, Web Application Firewall (WAF), and network security devices. Developed, tuned, and validated correlation rules and building blocks to detect security threats, including brute-force attacks, malware execution, privilege escalation, and suspicious authentication activities. Assisted in CRE rule and building block deployment, tuning, and validation to improve detection accuracy and reduce false positives. Performed SOC engineering activities including Event Collector (EC) and Event Processor (EP) integration, log source onboarding, and SIEM data flow validation using IBM QRADAR, SPLUNK. Validated log parsing, DSM mapping, event normalization, and correlation rules for newly integrated log sources using Event collectors, Universal forwarders, Event Processers, Heavy forwarders, Indexers using Qradar, Splunk. Documented incident findings, investigation details, and remediation recommendations while following SOC processes and SLA requirements. Performed 24x7 monitoring of SIEM offenses, events, and alerts, conducting daily alert analysis and initial incident investigations.
Education
Bachelor of Computer Science and Electronics, ECE - Acharya Nagarjuna University, Peddakakani
- 2022 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Need Sponsorship
Relocation
Open to Relocation
Skills (18)
Click a skill to find developers with the same skill