Cyber Security Engineer
CurrentCEH certified and having knowledge on phishing mail attack, DDoS attack, SQL injection attack, Brute force attack, Cross-site scripting (XSS),Kali Linux, Nmap scan, TCP DUMP, FW Monitor and Wireshark.SIEM: IBM Qradar/ QROC (QRadar on Cloud)• Administration and Investigation.• Event monitoring, Incident investigation and response.• Real-time monitoring and analyzing network traffic for unusual /suspicious activity.Netskope (CASB, DLP, Proxy, Zero Trust)• Cloud Access Security Broker (CASB) , Zero Trust network .• DLP, Inline policies.• Reverse and forward proxy configurations.• Threat protection, EDR integrations.EDR (Crowdstrike)• Deployment and administration.• Investigation of security incidents.• Configuring work flows, network containment policies.• USB DLP policies, RTR, Crowdstrike overwatch, IOC management.Threat intelligence, Sandbox: Anomali Threat streamBIA/ BCP/DR• Performing Business Impact Analysis (BIA) to identify the risk, process, application dependencies, staffing requirements. • Create Business Continuity Plan (BCP), and Disaster Recovery plan (DR) based on the outcome of BIA. VAPT/ Vulnerability Management: Tenable/Nessus/Qradar• Performing VA Scans using IBM Qradar And Tenable cloud (tenable.io).• Risk and vulnerability assessments• Participating in periodic audits, internal and external penetration testing. Analyzing the reports and mitigating the security risks.Audit, Gap Analysis: HIPAA , SOC• Gap assessment of information security policies. • Perform internal audit of security controls , HIPAA compliance. Identify the violations, missing controls, and implement.Incident/ Change Management: ServiceNow, Manage Engine, JIRA• Incident investigation, documentation, remediation. Service request through Manage Engine Service Desk and JIRA.Patching & Compliance: Bigfix• Patching and various compliance checks. System lifecycle management.