Senior Soc Engineer
Actively hunt for Indicators of Compromise (IOCs) and APT Tactics, Techniques, and Procedures (TTPs) in the infrastructure and organizing detections in the framework of MITRE ATT&CK.-Collaborate with the other fellow, SOC and Threat Analysts to create countermeasures to aid in future prevention and detection of cyber threat activity.-Leading and Investigating, potential security incidents response, possible vulnerabilities, and serve as a Lead Incident Handler to mitigate the incident.-Responsible for fine-tuning and to correlate various log sources via Splunk Enterprise Security by reviewing alerts generated by detection infrastructure for false positives and improve alerts as needed.-Contribute in writing, developing and optimizing use-cases, run books, and playbooks to manage various daily based security alerts.-Investigating and validating actionable security alerts/events and escalate or take action as indicated in the security model to mitigate threats.-Logs Analysis for Firewalls, Intrusion Detection and Prevention Systems, Email Security, DDoS Protection, Endpoint Detection Systems, Proxy Servers, Databases, and other Security Controls.-Working collaboratively with other technology teams in ensuring security programs are integrated into the overall development life-cycle and security findings are remediated within required remediation time-frames based on their severity.-Continuous capacity building of current and emerging cyber threats.