Cloud Security Administrator
Current•Securonix SIEM Integration with Cloud data Sources.•Windows/Linux servers hosted on Azure and AWS integration with SIEM Solution using NXlog/Syslog collection method.•Azure Network Security groups flow logs, Azure AD audit and Sign In logs, Azure Kubernetes service audit logs, Azure hosted databases audit logs, Azure Monitor activity logs, Microsoft defender for cloud, MS Defender suits logs, O365 audit logs, Sharepoint, exchange logs, Outlook, and etc integration with Securonix.•AWS cloud trail, AWS config, AWS EKS Audit, AWS GuardDuty, AWS RDS Cloudwatch, AWS Security Hub, AWS VPC flow logs integration with Securonix.•Trendmicro Deep Security manager log integration with Securonix.•Securonix SIEM policy creation, validation, and move to production for alerts.•Finetuning of SIEM use cases.•AVD standardization as per cloud security requirements.•MDI, MS Purview, O365 and M365 Implementation.•Defender for Storage Deployment.•Security gaps findings on Cloud environment.•SSO Integration for Cloud security solutions.•Cloud hosted devices onboarding on MDE, Trendmicro, Qualys.•Azure Key vault PMP solution management as owner.•Discussion with management on Compliance Reporting, Cloud Security Core report, Security Benchmarks Report, and Vulnerability Assessment reports.•Patch management.•Responsible for new Project Onboarding checklist validation.•Handling GTB DLP solution, upgrade activity, testing activity and deployment.•Handling Crowdstrike EDR solution, upgrade activity, testing activity and deployment.•Handling Cloud RIN server build activity.•Ensuring communication among DataSources and SIEM.•Logic apps creation for Vulnerability Assessment for Containers, Kubernetes services, databases, and other resources hosted on Azure and AWS.•Creation of runbook and use cases for SOC monitoring.•Process documentation and open risk tracker creation.Certifications:-Splunk Power User certified, SC 200, SC900, AZ500, AZ900