Security Operations Center Analyst
Monitored the security positions and network infrastructures of multiple environments using enterprise security tools such as Proofpoint, Splunk ES, SentinelOne, QRadar, and CrowdStrike to help ensure the security of the environments and assets.Worked on securing environments by monitoring, detecting and responding to end point security incidents such as malware infections, malicious activity by threat actors, suspicious user behavior and in parallel documenting any incidents, research and technical recommendations via Jira in conjunction with TheHive ticketing systems.Conducted investigations to validate the legitimacy of emails, files, domains and IP’s using online resources such as VirusTotal, URLscan, AnyRun, AbuseIPDB and MX Toolbox.Used Tenable.io and Acunetix to perform vulnerability assessments on networks, endpoints, and applications while documenting findings for potential security posture improvements.Experienced in analyzing PCAP files in Wireshark, investigating the details of the compromised hosts, and documenting IoC on the executive summary report.Used Splunk and QRadar for in depth analysis of security related events impacting the network and environment. In depth analysis of events to track path of threat and measure the risk associated with the threat and potential remediation actions from that point.