Soc Analyst
CurrentServed as Analyst in SOC operations for real-time monitoring, analyzing logs from various security/Industrial appliances.• Carrying out log monitoring and incident analysis for various devices such as Firewalls, IDS, IPS, database, web servers and so forth.• Security event analysis and intrusion detection by review and analysis of events generated by variouscomponents including IDS/IPS, firewalls, Routers, DB, OS and various types of security devices.• Work closely with business units to ensure that they know what and how to feed data into Splunk and to create network hierarchy, classify Log Sources within the Splunk SIEM.• Monitoring the customer network using SIEM tools–Qradar, Splunk.• Hands-on experience of End point detection and Response (EDR).• Performing Real-Time Monitoring, Investigation, Analysis, Reporting and Escalations of Security Events from multiple log sources.• Maintain keep understanding of evolving internet threats to ensure the security of client networks.• Contacting the customers directly in case of high priority incidents and helping the customer in the process of mitigating the attacks.• Determine the scope of security incident and its potential impact to Client network recommend steps to handle the security incident with all information and supporting evidence of security events.• Creation of reports and dashboards and rules fine tuning.• Identify, investigate or resolve security breaches and incidents.• Monitoring Dashboard to analyze the Data.• Initial trouble shooting with respect to Log Source Communication issues.• Working in GSOC (Global security Operation center) with multiple clients.• Creating Reports alerts and investigate issues identified during monitoring the live traffic.• Handling multiple customers globally analyzing the customer networks for potential security attacks.• Support security incident response processes in the event of a security breach by providing incidentreporting.