Incident Response Analyst
Current- Incident Handling and Response and Threat Analyst working in U.S. Army Regional Control Center, Southwest Asia (USARCC-SWA) in Defensive Cyber Operations Directorate (DCOD) section- Manage cyber defense ops for 12K+ network devices with 16K+ member subscribership- Focused use of CJCSI 6510.01F and 6510.01B | trained 11 team members in daily CND operations- Initiate computer incident handling procedures | investigate potential network compromises- Process and organize full lifecycle of JFHQ-DODIN TOs, OPORDS, CTOs, NSA PULSE notifications, DISA Tippers, SharkSeer and products from other threat reporting mechanisms- Utilize digital forensic tools: Microsoft Defender Endpoint (MDE), Security Onion, Army Endpoint Security System (AESS)/ePO, TYCHON, Gabriel Nimbus, Arcsight SIEM, ESM- Collaborate with threat intelligence analysts; provide indications and warning and contributes to predictive analysis of malicious activity; initiate triage to control/limit damage from Incidents- Enforce Network Security Violation and other policies | analyze data for trends and threats- Prepare organization for inspections; “Excellent” rating during annual (2021) CSSP inspection- Perform Threat Hunt(ing); search for malicious activity across networks and digital assets- Develop, document, and review Tactics, Techniques, and Procedures (TTP) and instructions- Prepare formal, comprehensive reports and presentations for technical and executive audiences- Gather evidence: establish chain of custody for use in UCMJ/criminal investigations