Information Security Analyst
CurrentCreate and track incidents and requests with an integrated ServiceNow (SNOW)ticketing system.Perform analysis of log files of Firewall, IPS, IDS, Server, and Proxy via Splunk SIEM solution.Skilled in performing thorough analysis of PCAP files using Wireshark, adept at extractingvaluable insights to troubleshoot network issues, identify security threats, and optimizenetwork performance.Identify, track, and investigate high-priority threat campaigns, malicious actors with theinterest, capability, and TTPs (Techniques, Tactics, and Procedures).Conduct core information security activities: Security Information and Event Management(SIEM), Malware Detection, Vulnerability Management, Education & Awareness, Open-SourceIntelligence (OSINT), Network Monitoring and Log Analysis. Monitor and analyze SecurityInformation and Event Management (SIEM) alerts through Splunk and identify securityincidents for remediation and investigation.Document all activities during an incident, provide management with status updates duringthe life cycle of it.Provide information and warning for intrusion events, security incidents, and other threatindications.Analyzing Qualys scan results to assess the severity of vulnerabilities and collaboratedwith cross-functional teams to develop targeted remediation plans.Assist in preforming and containment of compromised systems and mitigate root causes.Conducted in-depth analysis of security events and alerts within Splunk, providingactionable insights to the incident response team for timely mitigation.Develop and deliver security awareness and training programs to educate employeesabout cybersecurity best practices, policies, and procedures.Develop and implement an anti-phishing campaign periodically.Performing periodic scans in Qualys and inspecting and analyzing in ServiceNow(SNOW).Applied and managed security frameworks such as HIRA, NIST, ISO 27001 to enhanceand govern the organization’s information security strategies.