Senior Advisor, It Security
Current- Responsible for investigating high alerts, determining the source of the threat, the extent to which client assets have been compromised, making recommendations for remediation, and assisting in the implementation. - Advising on analysis of security events from multiple sources including but not limited to events from SIEM tools (Splunk, CTP, ArchSight, Q-Radar), network and host based IDS, firewall logs, system logs (Unix & Windows), mainframes, mid-range, applications and databases. - Collaborating with Line of Business technical teams for resolution and mitigation of detected issues. - Elaborating runbooks. - Routinely interacting with vulnerability and threat management teams and incorporate feedback into information security applications.- Supervising different incident response actions with internal and external teams while owning the responsibility for the incident/event until complete closure.