Soc Analyst
CurrentExperience working with SIEM - Qradar, CrowdStrike , Mcafee, RSA, Splunk, ArcSight, Azure Sentinel systems.• Gathering, analyzing, and processing alerts from many systems of cyber protection, handling cyberevents in real-time (Isolate workstations, remove malicious files, block IPs, etc.), and writing eventreports if necessary.• Experience with Mail investigations, File investigation (Dynamic & Static analysis), Proactive monitoring & Active threat hunting.• Hands-on experience in analyzing and investigating events by querying differentSystems - Palo Altoand more.• Knowledge in security and monitoring products: WAF, IPS, NAC, AV, DLP, PROXY, MR, SANDBOX, HONEYPOT FW(Microsoft Cloud App Security, Azure AD, imperva, vectra, Intezer Analyzer, EPO, ciscoAMP, Ironport, Trend Micro proofpoint, DarkTrace, Malware Bytes, Illusive and more)• Understanding of Windows and Linux processes.• Querying systems using KQL, AQL and SPL (Splunk).• Quickly perceives what happened and what needs to be done during cyber Incidents in real- time.• Quick adaptation to different work environments and systems.• Working with clients around the world.Experience in gathering Threat Intelligence with various tools- OSINT