Cyber Security Analyst
Current• SOC Monitoring and Incident Reporting: Conducted real-time monitoring of security events and generated comprehensive incident reports to document security incidents and the actions taken.• Dashboarding: Configured and optimized dashboards within the SIEM platform to enhance daily security monitoring and facilitate quick analysis of security data.• Logging Levels Review: Regularly reviewed and adjusted logging levels across various integrated log sources to ensure comprehensive data collection and optimal performance.• Threat Advisory Management: Proactively addressed and escalated relevant threat advisories, tailoring responses to meet client-specific requirements and implementing measures to block active IOCs on relevant controls.• Phishing Incident Response: Managed phishing incidents by performing detailed analysis of email headers and other indicators to mitigate potential threats and reduce client exposure.• Use Case Definition and Tuning: Defined and refined use cases for alert generation, and conducted troubleshooting to ensure the accuracy and effectiveness of implemented use cases.• Runbook/Playbook Creation: Developed detailed runbooks and playbooks for responding to triggered alerts, enhancing the efficiency and consistency of incident response procedures.• Incident Metrics Reporting: Developed and maintained incident metrics reports, including Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), and Mean Time to Mitigate (MTTM), to track and improve incident response performance.