Cyber Security Analyst
CurrentI analyze logs and investigate unusual network activities and phishing events. I also monitor, assess, and remediate cybersecurity events to secure and protect sensitive data.● Monitor and analyze security events and alerts from multiple sources, including security information and event management (SIEM) software, network and host-based intrusion detection systems, firewall/Proxy logs, system logs (Windows and Unix), and databases.● Provide support to the Security Operations Center during incident response and threat-hunting activities that include cyber threat analysis support, research, recommending relevant remediation and mitigation.● Conducted detailed, comprehensive investigation and triage on various security events, implemented response and remediation efforts, and integrated and shared information with security analysts and other information security teams.● Review alerts generated by detection infrastructure for false positive alerts, modify alert rules and work with the engineering team to create suppression rules.● Regularly communicate with customer IT teams to inform them of issues, help them remediate, and ensure they continue to operate as usual.● Keep up to date on emerging vulnerability and threat trends. Collaborate with internal security partners to derive indications and warnings of impending threats, use this knowledge to drive proactive threat monitoring, and create innovative ways to use a wide range of security event data to advance detection methods and product capability.