Enterprise Incident Response Analyst
Current• Designed, implemented, and managed tools (ex. SIEM, EDR, SOAR, web proxy, etc.) that automatically monitor, detect, and report security-related events daily via emails and tickets.• Investigated and mitigated security incidents, working with other departments to contain and minimize damage.• Researched new sophisticated threats using OSINT (Open Source Intelligence) and threat intelligence tools (ex. Shodan, VirusTotal, URLScan.io, SecurityTrails, Internet Archive, MXToolbox, etc.).• Presented research analysis reports to upper management and the global security community.• Proactively hunted for new and sophisticated threats within our environment.• Dynamically and statically reverse engineered malicious files within a sandbox environment using tools within Mandiant Flare (ex. Floss, Cutter, Ghidra, x32dbg, Capa, Procmon, Wireshark, oledump, etc.).• Created playbooks and knowledge based articles for my team.• Performed penetration tests on pre-approved infrastructure using tools within Kali Linux (ex. BurpSuite, Nmap, Metasploit, Hashcat, John the Ripper, Mimikatz, etc.).• Created scripts using Bash, Python, and PowerShell.• Performed digital forensics on devices using a write blocker and forensic software.