Cyber Security Analyst
Current● Create and track incidents and requests with an integrated ServiceNow(SNOW) ticketing system.● Follow detailed operational processes and procedures to appropriately analyze, escalate, and assist in the remediation of security incidents.● Liaise with the Company’s Security Operation Center to respond to emerging incidents in a timely manner.● Perform analysis of log files of Firewall, IPS, IDS, Server, and Proxy via Splunk SIEM solution.● Analyze PCAP files for Malware analysis and find details of the infected hosts and write IOC on executive summary reports.● Identify, track, and investigate high-priority threat campaigns, malicious actors with the interest, capability, and TTPs (Techniques, Tactics, and Procedures).● Analyze and review escalated cases until closure.● Conduct core information security activities: Security Information and Event Management (SIEM), Malware Detection, Vulnerability Management, Education & Awareness, Open-Source Intelligence (OSINT), Network Monitoring and Log Analysis.● Monitor and analyze Security Information and Event Management (SIEM) alerts through Splunk and identify security incidents for remediation and investigation.● Document all activities during an incident and provide management with status updates during the life cycle of the incident.● Provide information regarding intrusion events, security incidents, and other threats indications and warning information to the client.