Incident Response Security Analyst
Current- Monitoring critical activities and alerts generated by logs from multiple sources (SIEM tools, network and host based IPS/IDS, firewall, etc) and performing incident response actions accordingly
- Identifying and responding to compromised user accounts based on deep sign-in analysis and user behavior
- Investigating alerts triggered by processes, services, communication with suspicious domains, unusual behaviour, etc, with efforts to determine a root cause and detect potential security breaches
- Targeted threat hunting of advanced threats in client environment using indicators of compromise
- Analyzing different types of phishing/scam/spam/legitimate/encrypted emails and performing email containment