Information Technology Analyst Ii (Csirt)
Current• Handled and monitored inbound phishing attacks that posed as a threat to the employees of Sacramento County.• Leveraged Splunk and CrowdStrike to preemptively hunt for potential threats across the network.• Proficiently analyzed and responded to security alerts and incidents using Microsoft 365 Defender and Falcon CrowdStrike in a SOC environment.• Created Cisco ESA filters to mitigate targeted phishing campaigns.• Developed and maintained custom detection rules and signatures to enhance threat detection and reduce false positives within the security tools, optimizing the SOC's efficiency.• Collaborated with cross-functional teams to ensure timely and effective incident response, containment, and remediation activities using insights from M365 Defender, Falcon CrowdStrike, Cisco IronPort, and Splunk.• Stayed up to date with the latest threat intelligence and security trends, integrating this knowledge into daily SOC activities to proactively defend against emerging threats.