Cyber Security Analyst
Current• Create and manage requests and incidents using an integrated ServiceNow (SNOW) ticketing system.• Adhere to comprehensive operational protocols and guidelines to effectively• Examine, report, and help resolve security incidents.• Communicate with the Security Operation Centre of the company to promptly address emergent incidents.• Use the Splunk SIEM solution to analyse log files from servers, firewalls, intrusion prevention systems, and proxy servers.• Search for information about the compromised hosts, analyse PCAP files for malware, and write the IOC on executive summary reports.• Recognise, follow, and look into hostile actors with the intent, means, and TTPs (techniques, tactics, and procedures) as well as high-priority threat campaigns.• Examine and evaluate cases that have been escalated until they are resolved.• Perform the following essential information security tasks: manage vulnerabilities, detect malware, educate the public, use open-source intelligence (OSINT), monitor networks, and analyse logs.• Track and examine Security Information and Event Management (SIEM) notifications using Splunk, identifying security issues for follow-up and examination.• Throughout the course of the incident, keep track of every action taken and inform management of any developments.• Provide the client with information about security incidents, intrusion events, and other threat indicators and warnings.