Soc Analyst
Current-Conduct log analysis on Splunk Enterprise Security and IBM’s QRadar SIEM solutions, providing recommendations to technical teams.-Monitor and analyze SIEM alerts via Splunk Enterprise Security and IBM’s QRadar, identifying security anomalies for investigation and remediation.-Analyze files, domains, and emails for legitimacy using VirusTotal, AnyRun, and MX Toolbox.-Examine Packet Capture (PCAP) files, detail infected hosts, and write Indicators of Compromise (IOC) in executive summary reports.-Diagnose common cyber-attack types and create examples using Setoolkit in Kali Linux.-Review policies for compliance with the National Institute of Standards and Technology (NIST) Risk Framework.-Configure and manage Fortinet NextGen Firewalls, DNS Security, Website Proxies, and Intrusion Prevention Systems (IPS).-Implement Application Security measures and manage VPNs for secure remote access.-Learn Windows and Linux Fundamentals to support security operations.-Conduct Wireshark Fundamentals training and perform detailed PCAP analysis.Introduction to Vulnerability Management, using Tenable.io and Nessus for vulnerability scanning and assessment.Conduct Web Application Security assessments with Acunetix.Utilize Threat Intelligence tools such as Acunetix, Armis, and OSINT tools for asset management and IoT security.Manage Email Security using ProofPoint and Resilient, handling phishing cases and social engineering attacks.Work with Ticketing Systems like Jira to track and manage security incidents.Introduction to End-Point Detection and Response (EDR), focusing on SentinelOne and CrowdStrike EDR/XDR tools.Security Operations Center (SOC) shifts and challenges, gaining practical experience in a real-world SOC environment.Use of SentinelOne EDR/XDR for advanced threat detection and response.Continued use of QRadar for log analysis and security event management.Introduction to Splunk Enterprise Security and its use cases for comprehensive security monitoring.