Strategic SOC Analyst with experience devising and implementing robust solutions and improvement strategies. Met cost, quality and timescale constraints to achieve objectives. Communicates confidently to engage technical and non-technical stakeholders, aiding achievement of key deliverables.
Enthusiastic SOC Analyst with 07 years of experience. Secures team success through hard work, attention to detail and excellent organisation.
Having overall 8.3 years of experience in IT industry.
Customer-oriented SOC Analyst with strong history of leading high-performance teams to meet or exceed objectives. Dedicated and hardworking with internal drive to deliver excellence. Tactical team builder with strong background in training and team development.
Performing Real-Time Monitoring, Investigation, Analysis, Reporting and Escalations of security Events from Multiple log sources.
Experience in monitoring & investigating incoming Events in a network.
Good knowledge on networking concepts including OSI layers, subnet, TCP/IP, Ports, DNS etc.
Carrying out log monitoring and incident analysis for various devices such as Firewalls, Routers, IDS, IPS, database, web servers and so forth.
Website Anti-Malware and Defacement monitoring and real-time alerting based on anomalies detected
Monitoring 24x7 for Security Alerts and targeted phishing sites by using SIEM tool with the help of technologies such as Watermark, Referrer, Abuse mailbox and similar sounding domains.
Exposure to Ticketing tools like BMC Remedy, HP Service manager.
Develop content for SIEM by writing correlation rules, dashboards, reports and alerts.
Vulnerability scanning and Assessment using Nessus tools and categorization of vulnerability based on criticality.
Contacting the customers directly in case of high priority incidents and helping the customer in the process of mitigating the attacks.
Solution-focused Cyber Security Analyst with incident and vulnerability analysis expertise. Monitors new and emerging technologies to innovate risk management. Proactive and adaptive to deliver targeted remedial action, maintaining best practices.
Talented individual seeks Cyber Security Analyst position to support delivery of resilient processes and procedures. Knowledgeable in attacker exploitation techniques for improved threat management. Collaborative team player, aiding productivity across complex projects.
Committed manager with exceptional leadership, organisational skills and communication abilities leads high-performing cross-functional teams. Leads projects, company operations and business growth.
Takes on challenging new role harnessing interpersonal skills, collaboration and problem-solving. Driven to deliver high-quality service and consistent results.
Resourceful employee with outstanding knowledge to develop and maintain healthy customer pipeline. Consistently works to attract new business opportunities. Talent in administrative oversight, recruitment processes and customer service improvements.
Overview
9
9
years of professional experience
Work history
L2- Cyber Security Consultant
KBS Technologies Ltd
2023.01 - Current
Monitoring Security alerts generated by SIEM.
Analyzing SIEM alerts by following run-books and using various tools.
Investigating incidents, remediation, tracking and follow-up for incident closure with concerned teams.
Triaged and responded to alerts to reduce harm to critical data and systems.
Assessed application and infrastructure security to find and address vulnerabilities.
Deployed patches and security updates to protect ICT assets from malicious attacks.
Encrypted data transmissions and erected firewalls to conceal confidential information.
Deployed VPN for personnel use and protection.
Architected systems to minimise potential intrusion points and overall security weaknesses.
Limited ICT service outages with successful preventative maintenance strategies.
Maintained system compliance with legal requirements and company security standards.
Monitored computer virus reports and regularly updated virus protection systems.
Helped develop playbooks and exercises for incident response and remediation.
Partnered with security professionals to identify and address problems through incident validation and action synchronization.
Coordinated emergency disaster recovery, minimising data loss and supporting business continuity.
Removed computer viruses and malware from affected computers, collaborating with security team to analyse security-related incidents.
Communicated security incidents to customers and stakeholders for compliance reasons.
Acknowledging and closing false positives and raising tickets for validated incidents.
Doing Raw log analysis of the alerts triggered on SIEM tool.
Had done vulnerability scan using NESSUS tool while working with cross functional team.
Handling L1 network related issues and alarm monitoring.
Develop content for SIEM by writing correlation rules, dashboards, reports and alerts.
Co-ordinate with auditing and compliance team by providing requested report and data.
Provide feedback for all outages in network related to transmission issues.
Responsible for finding the network faults/ Outages, and analyzing their root cause.
Participate in weekly meetings to discuss about incidents raised and Secondary job is Vulnerability scanning and Assessment using Nessus tools and categorization of vulnerability based on criticality.
Draft shift handovers in the end of the shift for all incidents and number of alerts
Worked with application teams in applying secure practices to software implementation.
Monitored new threats, vulnerabilities and attacks and applied countermeasures to prevent intrusion.
Discussed data access needs, security violations and programming changes with system users to resolve issues.
Assisted security teams with threat signature implementation and tuning.
Established IT investigative practices to streamline diagnosis and resolution, minimising downtime and enhancing system performance.
Promoted and trained systems users in security awareness to maintain system security.
Mentored and supervised junior analysts to sharpen security skills and grow talent pools.
Suggested new use cases to expand visibility and coverage of attack surfaces.
Contributed to design and development of security tools for monitoring company assets.
Conducted ongoing threat monitoring and targeted audits on systems.
Drafted security governance policies and procedures for company assets.
Analysed security breaches to determine root causes.
Recommended preventive security measures to decrease attack surfaces.
Developed solutions to limit access to protected data and programs.
Tested security measures and systems, performing risk assessments to detect vulnerabilities.
Developed disaster recovery plans for critical assets to keep services operational.
Analysed data and information to identify issues and create tailored solutions.
Monitored and updated stock levels and inventory databases.
Used Microsoft Word and other software tools to create documents and clear communications.
Operated machinery to achieve targets while following regulations.
Completed duties to deliver on targets with accuracy and efficiency.
Offered friendly, efficient customer service and handled challenging situations with ease.
Conducted testing to diagnose system faults.
Displayed energy and enthusiasm in fast-paced environment.
Promoted continuous improvement by problem-solving and sharing suggestions to optimise team operations.
Cleaned work areas and equipment to maintain faultless hygiene standards.
Handled high volume calls to address customer inquiries and concerns.
Consistently arrived at work on time and ready to start immediately.
Supported team by demonstrating respect and willingness to help.
Increased customer satisfaction by resolving issues.
Developed plans and strategies to promote continuous improvement.
L1- Security Analyst
TPSC-1 Pvt. Ltd
, India
2021.03 - 2022.05
Responsible for initial analysis, identification, remediation, and documentation of Security Incidents.
Monitored computer virus reports and regularly updated virus protection systems.
Conducted security audits to identify vulnerabilities.
Reviewed breaches of computer security procedures and developed mitigation plans.
Removed computer viruses and malware from affected computers, collaborating with security team to analyse security-related incidents.
Encrypted data transmissions and erected firewalls to conceal confidential information.
Discussed data access needs, security violations and programming changes with system users to resolve issues.
Encrypted data and erected firewalls to protect confidential information.
Engineered, maintained and repaired security systems and programmable logic controls.
Deployed VPN for personnel use and protection.
Monitored computer virus reports to determine when to update virus protection systems.
Developed solutions to limit access to protected data and programs.
Maintained system compliance with legal requirements and company security standards.
Tested security measures and systems, performing risk assessments to detect vulnerabilities.
Managed high volume of 04 projects according to quality, schedule and budget targets.
Partnered with security professionals to identify and address problems through incident validation and action synchronization.
Performed risk analyses to identify appropriate security countermeasures.
Oversaw network architecture and security, defining policies and procedures for successful operations.
Monitored use of data files and regulated access to protect secure information.
Recommend improvements in security systems and procedures.
Limited ICT service outages with successful preventative maintenance strategies.
Coordinated emergency disaster recovery, minimising data loss and supporting business continuity.
Conducted ongoing threat monitoring and targeted audits on systems.
Oversaw team of 60 ICT security personnel minimizing risks and swiftly resolving breaches.
Promoted and trained systems users in security awareness to maintain system security.
Established IT investigative practices to streamline diagnosis and resolution, minimising downtime and enhancing system performance.
Developed plans to safeguard computer files against modification, destruction or disclosure.
Wrote reports outlining project progress and results.
Handled high volume calls to address customer inquiries and concerns.
Successfully delivered on tasks within tight deadlines.
Generated Key Performance Indicator reporting to drive better performance.
Conducted testing to diagnose system faults.
Work closely with functional senior leaders to ensure threat intelligence analysis and products are mapped to prioritized corporate assets and risks.
Managed Cyber Security threats through prevention, detection, response, escalation and reporting in effort to protect Enterprise IT Assets through Computer Security Incident Response Team (CSIRT).
Blacklist feeds sourced from open internet, threat exchange communities, vendor research and research blogs.
Weekly Threat Advisory report with summary of generic threats reported over the past, Ensured the security platform is performing optimally and security events are detected quickly and remediated.
Managed security tools provide system administrative support and maintain and upgrade tool sets, Managed and executed multi-level responses and addresses reported or detected incidents, Performed information security incident response and incident handling based on risk categorization and in accordance with established procedures.
Identifying incidents and make recommendations to protect the network.
Assist in the administration and integration of security tools(SIEM)to include new data/log sources, expanding network visibility and automation.
Worked on identifying the levels of vulnerabilities on applications (High, Medium and Low) in order to provide overall security posture and prioritize the issues which are at high level based on OWASP Top10, Identifying OWASP Top10 Issues identifications like SQL Injection, CSRF, XSS and invalidated redirects and forwards etc.
Monitored and updated stock levels and inventory databases.
Demonstrated respect, friendliness and willingness to help wherever needed.
Increased customer satisfaction by resolving issues.
Processed invoices and payment runs with complete accuracy.
Developed appropriate resources to meet needs of diverse audiences.
Analysed reporting to reconcile transactions, accounts and ledgers.
Promoted continuous improvement by problem-solving and sharing suggestions to optimise team operations.
Handled high-volume telephone and email enquiries to minimise backlogs.
Managed on-site evaluations, internal audits and customer surveys.
Worked flexible hours, covering nights, weekends and bank holidays.
Security Analyst
Toshiba Plant Systems & Services Corp (TPSC Engineering)
, India
2018.01 - 2021.02
Working in Security Operation Centre (24/7), monitoring of SOC events.
Detecting and Preventing the Intrusion attempts, Working on Email Gateway Analysis, Phishing Analysis, proxy analysis MS ATA, MS ATP, Deception, and SEP end point protection.
Recognize successful and attempt of cyber intrusions and compromises through log review and analysis of relevant event detail information.
Development of Reports and Dashboards in Log Rhythm, RSA Net witness, Recognizing attacks based on their signatures.
Understanding phases of Log Rhythm, RSA Net witness ESM event life cycle and describe the functional processing which occurs during each phase.
Using AV and other analysis tools to perform Malware Analysis and complete removal of malware from client's environment.
Differentiate the false positives from true intrusion attempts and help remediate / prevent.
Support escalation and work closely with stakeholders as required, Document all actions taken during incident investigations.
Provide tuning and filtering recommendations to engineering teams.
Support requests for data by the customer and other teams analyzing daily, weekly and monthly reports.
Research, analysis, and response for alerts; including log retrieval and documentation.
Monitoring and carrying out second level analysis incidents.
Analyse and investigate the alerts in SOC monitoring tool to report any abnormal behaviours, suspicious activities, traffic anomalies etc.
Conduct analysis of network traffic and host activity across a wide array of technologies and platforms.
Assist in incident response activities such as host triage and retrieval, malware analysis, remote system analysis, end-user interviews, and remediation efforts.
Recognize cyber-attacks based on their signatures, Differentiate the false positives from true intrusion attempts and help remediate/prevent cyber-attacks.
Analyse malicious campaigns and evaluate effectiveness of security technologies.
Develop advanced queries and alerts to detect adversary actions.
Lead response and investigation efforts into advanced/targeted attacks.
Identify gaps in IT infrastructure by milking an attacker's behaviours and responses.
Provide expert analytic investigative support of large scale and complex security incidents.
Direct prior experience with core security technologies (SIEM, firewalls, DLP, IDS/IPS, HIPS, proxies, vulnerability scanners, AV, etc.).
Work closely with other teams to support the incident management process
System Admin Engineer
Akshara International Schools
, India
2017.02 - 2017.11
Configuring, managing and troubleshooting local user accounts and group accounts.
Configuring, managing & troubleshooting Outlook application, AD Server and DHC.
Thorough knowledge on all kind of laptop, Desktop & Servers related issues.
Supported management decision-making with expert-level technical guidance.
Devised and implemented test procedures to verify product compliance and performance.
Resolved complex issues, applying troubleshooting and critical thinking to address numerous technical solutions.
Monitored KPIs and implemented swift change management to address potential delays.
Collaborated with procurement team to secure project materials at favourable prices.
Resolved conflicts and negotiated mutually beneficial agreements between parties.
Designed digital and print materials to engage audiences.
Delivered exceptional customer service by proactively listening to concerns and answering questions.
Improved efficiency and productivity by acquiring new skills.
Quality Department - Internship
Tata Lockheed Martin Aero structures limited
, India
2015.06 - 2016.08
Proficiency in explaining the perfect scenario of Material quality to the client.
Developed Excel-based documentation and reports to decrease product complaints.
Strong knowledge of Microsoft Excel, PowerPoint, Word and Access, Highly developed management, leadership, and executive skills to lead an entire staff of employees.
Extensive knowledge of managerial tasks and CRISP-DM methodology.
Able to identify insights from the data and help the client to take right decisions.
Well-organized in fulfilling administrative tasks and following workflows.
Strong decision-making, critical thinking, evaluation, and analytical skills.
Used strong work ethic to meet stringent deadlines.
Generated written materials with meticulous attention to grammar and spelling.
Organised documentation and creatives to prepare for publication.
Addressed incoming requests for information, inquiries, and complaints.
Answered phone calls and emails for management team during busy periods.
Collected customer information for new orders, verified details and obtained missing data to meet project requirements.
Participated in staff meetings to discuss latest developments.
Communicated ideas and information clearly and concisely, both verbally and in writing
Fielded requests from information from outside parties and wrote professional correspondence in response.
Drafted outgoing correspondence in appropriate tone and style.
Used problem-solving skills to resolve challenges and prioritise workload.
Made positive contributions to team and workplace, consistently exceeding expectations.
Handled high volume calls to address customer inquiries and concerns.
Education
B.Tech -
SRI INDU ENGINEERING AND TECHNOLOGY
Hyderabad,India
06/2011 - 05/2015
Skills
SIEM (Security Information and Event Management) Tool: QRadar, ArcSight,Ms Sentinel
Networking: TCP/IP,OSI, VPN
Security Devices: Check Point, Palo Alto, WAF, Symantec Mail Gateway