Security Operation Anaylst L1
Abu Dhabi, United Arab Emirates
• Working on the Security Event Management team, providing Level 1 operations support at the Security Operations Centre using Microsoft Sentinel.• Monitoring Cloud based resources - AWS workloads and Azure services and implementing them to Microsoft SIEM tool – Microsoft Sentinel.• Mitigation of threats using Microsoft 365 Defender, Microsoft Defender for cloud and Microsoft Sentinel.• Investigation, analysis, reporting and escalations of security events from multiple cloud sources including events like AWS Guard duty, AWS Cloud trail, AWS VPCFlow, Azure Active Directory, Identity protection, MCAS. • Assisted with incident response efforts by providing analysis of collected evidence using Microsoft Sentinel.• Assisted in creating custom and analytic rules based on customer requirements. • Manage the SOC mailbox, and monitor and analyze the emails for threats including phishing and malware, and escalates per procedure• Performed security assessments of Azure environments and provided recommendations to improve the overall security posture of customers’ environments.• Monitored security compliance and investigated security breaches or violations using Defender for Microsoft 365.