Security Analyst
CurrentMonitor and analyse security events and incidents within a Security Operations Centre (SOC) environment to detect and prevent intrusion attempts.Utilized QRadar, a SIEM (Security Information and Event Management) tool, to monitor real-time events, ensuring timely detection and response to security incidents.Prepared comprehensive daily, weekly, and monthly reports according to client requirements, providing valuable insights into security posture and incident trends.Investigated and created cases for security threats, collaborating with the Onsite SOC team for further investigation and necessary actions.Possessed a solid understanding of OSI models, protocols, WAN and LAN concepts, routing protocols, firewall security policies, and VPN technologies.Integrated IDS/IPS (Intrusion Detection System/Intrusion Prevention System) to Confidential ESM and effectively analysed logs to filter out false positives and enhance rule sets.Configured and managed Nessus Scanner with the latest security center version, conducting vulnerability assessments for proactive security measures.Integrated various devices' data into Qradar & Splunk environment, creating dashboards and reports for enhanced visibility and threat analysis.Monitored and identified suspicious events using the Confidential ESM console, promptly raising tickets for appropriate actions.Implemented and deployed Symantec DLP, McAfee ePO, and NIDS (Network Intrusion Detection System) policies to safeguard the organization against evolving threats.Ensured continuous monitoring of traffic status, appliance health, and server health, verifying their optimal functionality.Managed and monitored security technologies to prevent, detect, and respond to potential threats.Worked on incidents and performed detailed analysis of alerts, reviewing, and triaging them based on predefined SLAs.