Cyber Security Operations Analyst
CurrentI monitor, detect, and respond to cyber threats using a suite of advanced tools. Microsoft Defender 365 provides endpoint protection and threat detection across devices, while Microsoft Azure ensures cloud security and compliance. I use Splunk as the Security Information and Event Management (SIEM) system to aggregate and analyze log data for suspicious activities. Anomali helps me identify and correlate external threats with its threat intelligence capabilities. For malware analysis, I rely on Reversing Labs and AnyRun to examine malicious software in-depth. Palo Alto XSoar allows me to orchestrate and automate security operations, streamlining incident response. With these tools, I ensure continuous surveillance of network traffic, system logs, and user activities, quickly identifying and responding to security incidents to minimize impact and ensure swift recovery. By integrating threat intelligence and conducting forensic investigations, I enhance the organization's security posture, providing comprehensive oversight and regular compliance reporting to defend against the evolving landscape of cyber threats.