Senior Information Technology Security Analyst
CurrentReceive incidents in Splunk SIEM under the Incident Response category.1. Assigning and prioritizing incidents according to urgency: medium, high or critical.2. Also monitoring malware incidents and suspicious activities on hosts and servers using Crowdstrike EDR.3. Basic Malware Analysis from EDR Alerts.4. Analysis of logs from various sources (e.g. IDS/IPS, firewall, DHCP).5. Searching for rogue devices connected to the client's internal network.6. Investigating phishing and social engineering emails reported by users.Working with with the customer's L3 team to resolve/escalate major incidents.