Global It Security Analyst
• Developed and led Chromalloy’s security awareness program, which included a monthly newsletter, phishing test, and companywide security lunch and learns to educate employees on cybersecurity best practices. • Developed a program that gamifies security education, to increase employee buy-in, by awarding individuals as well as sites based on performance on security task • Created monthly reports for the Global IT and senior leadership teams based on phishing and social engineering campaigns. • Developed training and formal corrective action policy for repeated failures on the phishing test • Managed the relationship with MSP and EDR service providers to ensure proper coverage and was the escalation point for incident response. • Developed Chromalloy’s threat intelligence program to ingest new TTPs into security tools as well as for cyber threat hunts increasing the team’s ability to track new threats and malicious activity.• Created a cyber threat hunting program to conduct routine hunts to proactively search for cyber threats and IOCs using ReliaQuest threat hunting tool for the past year and a half and previously Azure Sentinel to analyze network traffic and Trend Micro for endpoint logs. • Managed the process for the procurement of new MSP and EDR providers including defined our requirements via a decision matrix, sourced viable candidates, scheduled and conducted proof of concept trials, and managed the relationship with the vendors to ensure the best pricing. • Monitored and performed technical analysis and incident response using the CrowdStrike EDR, Azure AD/Sentinel, QRadar, and Wazuh information security solutions.