Security Operations Center Analyst L2
CurrentWork closely with the SOC team and be responsible for incident detection, triage, analysis, response and report remediation actions.Experience on the Security information and event management (SIEM) tools like USM Anywhere, AlienVault Appliance, Security Onion.Recognize successful intrusions and compromises through review and analysis of relevant event detail information.Identify and recommend the false positives or alerts required fine-tuning to enhance the SOC operations efficiencyActively investigates the latest security vulnerabilities, also do Vulnerability assessment and prepare advisories reports for end users or clients.Conduct different types of investigation like Intelligence based , domain based , Kill chain and MITRE based.Collect, analyze, and interpret data from OSINT tools like Shodan,theHarvester,Censys,DNSDumpster,maltego to identify potential threats and vulnerabilities.Manage day-to-day operations of endpoint security tools such as MalwareBytes and Bit Defender.Implement and update the policies and configurations of the EDR solutions.Investigate malicious phishing emails,domains and IPs using open source tools like phishtool and MXtoolbox.Monitor acronis which include Local backup of system and server, Email Protection and Software Management.Perform vulnerability assessments testing using tools such as Nessus, Acunetix , NMAP, TestSSL, and WPScan.Deploy, Troubleshoot, and Test security solutions via Fourcore across all clients..SIEM Tool: USM Anywhere, AlienVault Appliance, Security Onion.EDR: Malwarebytes, BitdefenderOther Tool: Acronis,Joe Sandbox, URLScan.io, Phish Tool,Mxtoolbox, and Any.Run , Shodan ,Theharvester ,C Censys , DNSDumpster , Maltego, FourCoreThreat Intelligence tool: VirusTotal OTX,Hybrid Analysis,