Principal Cyber Security Engineer
Current- Working as Tier 2 SOC Analyst and providing services to different customers.- Utilize advanced SIEM platforms such as QRadar to monitor network traffic and identify potential security incidents and risks.- Monitoring and analyzing security events using Microsoft XDR solutions such as Microsoft Defender for Endpoint, MDO, MDI, and Microsoft Defender for Cloud apps.- Utilize various threat intelligence platforms to detect and analyze Indicators of Compromise (IOCs) in the organization's infrastructure.- Escalation of incidents to the clients w.r.t relevant team.- Monitor and maintain the health of SIEM systems through regular checks.- Evaluate and manage relationships with DLP solution vendors, including assessing new technologies, negotiating contracts, and overseeing implementation and maintenance activities.- Conduct regular risk assessments to identify potential vulnerabilities and threats to sensitive data, proposing and implementing proactive measures to mitigate risks effectively- Developing and implementing the DLP strategy for the organization, which includes policies, procedures, and technologies to prevent data leakage.- Defining and managing DLP policies, rules, and classifications to identify and protect sensitive data- Ensuring that the organization complies with relevant EU and US data protection laws, and International Best Practices- Developing different reports on DLP metrics, incidents, and the overall effectiveness of the DLP program to senior management- Monitoring and analyzing cloud security and backup metrics and logs using centralized logging and monitoring tools like AWS CloudWatch and Azure Monitor, proactively identifying security incidents, backup failures, and performance issues, and initiating timely remediation actions.- Implementing DevSecOps practices to seamlessly integrate security into the software development lifecycle.