Senior Security Analyst
Current• Being part of MSSP organization, monitored SIEM(QRadar, ArcSight, Securonix) consoles for various customers and fine-tuned false positive alerts in generic and custom specific.• Reviewing alerts escalated by L1 team and assisting them in reporting triggered alerts.• Working in 24x7 SOC operations, which included detection, tracking, and analyzing incident alerts and generating daily, weekly, and monthly reports and preparing them in the proper format to share them with customers.•… Show more • Being part of MSSP organization, monitored SIEM(QRadar, ArcSight, Securonix) consoles for various customers and fine-tuned false positive alerts in generic and custom specific.• Reviewing alerts escalated by L1 team and assisting them in reporting triggered alerts.• Working in 24x7 SOC operations, which included detection, tracking, and analyzing incident alerts and generating daily, weekly, and monthly reports and preparing them in the proper format to share them with customers.• Creation of rules, reports, and dashboards in SIEM tools as per stakeholders requirements.• Providing advisories and configuring IOCs to block based on the client environment. Performing analysis for multiple phishing emails which are reported by end users.• Have exposure in monitoring Microsoft Windows Defender ATP, Brand monitoring on iZOOlogic platform. Assist in providing proper mitigation steps.• Prepared RCA document for security incidents thoroughly, maintaining accurate records of incident details, actions taken, and lessons learned for post-incident analysis and improvement.• Preparing and providing log stoppage devices list for customers.• Review of daily health Check : QRadar and their components. Troubleshooting non-reporting devices and maintain device status reporting Troubleshooting issues occurred on daily health check & system notifications. Show less