Event Response Analyst
Current• Monitored and analyzed security events and alerts to identify potential threats or breaches within both client and the internal environment.• Lead complex incident investigations including triage, containment, eradication, evidence collection, after-action reporting, and documentation• Performed investigations into artifacts unavailable in existing security tools (log/host-based artifact identification and collection)• Coordinated with both internal and external resources during incident management• Performed forensic investigation and data collection within a wide range of environments in collaboration with client teams and resources• Utilized a wide range of tools and operating systems including EDR/XDRs, SIEMs, firewalls, IPS/IDSs, ticketing systems, user management, Linux, and Windows• Created and edited playbooks in SOAR platform