Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic

RAHUL JACOB

Cyber Security Analyst
Blackpool,BPL

Summary

Cyber Security Analyst with over 5 years of experience in security operations, incident response, and vulnerability management. Proven track record in enhancing threat detection efficiency, reducing false positives, and implementing high-fidelity detection rules. Adept in SIEM tools, real-time log analysis, threat hunting, and cloud security. Currently seeking to leverage expertise to contribute to a Senior Security Analyst role in a dynamic and challenging environment.

Overview

5
5
years of professional experience
4
4
years of post-secondary education
6
6
Certifications

Work History

Cybersecurity Analyst

University of Dundee
09.2023 - Current
  • Conducted quarterly reviews of user access rights, reducing risk of insider threats and compromised accounts by 15%.
  • Analysed security incidents post-resolution and identified key areas for improvement, resulting in 20% enhancement in technical controls and incident response efficiency.
  • Reduced risk of cyber attacks by 30% through regular vulnerability assessments and timely remediation of identified risks.
  • Enhanced network security by implementing advanced threat detection systems, leading to 25% increase in detection and prevention of potential threats.
  • Improved incident response times by 40% by developing and maintaining comprehensive cybersecurity playbooks for common attack scenarios.
  • Collaborated with IT teams to integrate security measures, ensuring that 100% of new applications met security standards before deployment.
  • Customized and managed SIEM systems for real-time threat detection, which improved accuracy of threat analysis by 35%.
  • Led cybersecurity awareness training sessions for over 50 staff members, increasing vigilance against phishing and social engineering attacks by 50%.

Security Analyst

Help A G
01.2022 - 07.2023
  • Analyse potential, successful and unsuccessful intrusion attempts and compromises using correlation analysis of event details and developing data-driven reports to present findings and preventive action plans.
  • Investigate malicious phishing e-mails, domains and IPs using sector intelligence tools and raise requests to block IP/domains, in line with SLAs.
  • Monitor, analyse and validate incidents triggered by correlated events through SIEM Solution and was recognised for maintaining high KPI achievement.
  • Worked with the security engineers to review risk management framework and compliance tracking measures and implement endpoint protection solutions to improve threat detection & response capability.
  • Collaborated with SOC Engineers and Operations to analyse anomalous or suspicious events and continuously implement high-fidelity detection rules.
  • Perform real-time log analysis from heterogeneous devices including firewalls, EDR, NDR, IPS/IDS, Endpoints and Servers and normalized IP addresses, timestamps and other data which helped to improve troubleshooting efficiency by 12%.
  • Performed IoC-based threat hunting and documented findings relating to user activity monitoring, data accumulation and unusual network traffic patterns, improving knowledge of IT team.
  • Performing vulnerability scans of assets and assigning discovered CVEs to respective BOs for patching and remediation.
  • Developed a comprehensive watchlist for Carbon Black EDR solution to anticipate and detect various threats and provided actionable insights to simplify operations.
  • Assist SOC operations team to research industry trends and new technologies and implement future product road maps focusing on threat resilience, data analytics, automation and security best practices.

Cybersecurity Analyst

Wipro Technologies
07.2019 - 12.2022
  • Analyse triggered rules in Qradar on a weekly basis and performed fine-tuning which resulted in reducing false positives by 4%.
  • Developed and maintained use-case playbooks, checklists, and standard operating procedures (SOPs) and created workflows to share across internal teams and customers, improving transparency.
  • Monitored incoming alert queues for potential security incidents and performed initial investigation, analysis, and triage with a high level of accuracy and efficiency.
  • Collaborated with security engineers to continuously review and improve prioritization and categorization rules in line with risk profiles.
  • Developed rules for IOC's list data for proactive monitoring measures which improved overall threat intelligence capability.
  • Installed ArcSight ESM 7.4 and other tasks including migration to production server, upgrading ArcSight Management Center (ArcMC).
  • Completed key integrations including CrowdStrike using Falcon and NetSkope using logstash, improving operational efficiency, troubleshooting time and service levels.
  • Contributed to continuing development of SOC architecture, processes, procedures, standards, and methodologies.
  • Developed weekly reports showcasing raised incidents, detailed analysis of events or alert and recommended action plans to mitigate and prevent reoccurrence.
  • Reduced false positive alerts in security monitoring systems by fine-tuning detection parameters, enhancing operational efficiency.

Education

Bachelor of Technology - Computer Science

Albertian Institute of Science And Technology
08.2015 - 05.2019

Skills

Network Security

Vulnerability Assessment

Incident Response Management

Phishing Detection

Endpoint Protection

SIEM management

Log Analysis

Security Operations Center

Social Engineering Prevention

Teamwork and Collaboration

Decision-Making

Time Management

Analytical Thinking

Certification

Microsoft Security Operations Analyst (QA)

Timeline

Cybersecurity Analyst

University of Dundee
09.2023 - Current

Security Analyst

Help A G
01.2022 - 07.2023

Cybersecurity Analyst

Wipro Technologies
07.2019 - 12.2022

Bachelor of Technology - Computer Science

Albertian Institute of Science And Technology
08.2015 - 05.2019

Microsoft Security Operations Analyst (QA)

Cyber Primer (QA)

Cyber Security Fundamentals Pathway (QA)

Google Associate Cloud Engineer (Wipro Limited, 2020)

Google Cloud Platform (GCP) Fundamentals (Wipro Limited)

Linux Command Line Basics (Wipro Limited)

RAHUL JACOBCyber Security Analyst