Information Technology Analyst Ii (Csirt)
Current- Handled and monitored inbound phishing attacks that posed as a threat to the employees of Sacramento County.
- Leveraged Splunk and CrowdStrike to preemptively hunt for potential threats across the network.
- Proficiently analyzed and responded to security alerts and incidents using Microsoft 365 Defender and Falcon CrowdStrike in a SOC environment.
- Created Cisco ESA filters to mitigate targeted phishing campaigns.
- Developed and maintained custom detection rules and signatures to enhance threat detection and reduce false positives within the security tools, optimizing the SOC's efficiency.
- Collaborated with cross-functional teams to ensure timely and effective incident response, containment, and remediation activities using insights from M365 Defender, Falcon CrowdStrike, Cisco IronPort, and Splunk.