Security Analyst
Current(Client: Tech Mahindra, Abu Dhabi Municipality-DMT Project, Abu Dhabi, UAE)•Responsible for handling the alerts escalated by L1 Teams/Tools which includes ADDA SOC Team, Threat Intel Team, if the - alerts is a true positive or a false positive and set up actionable / remediation.•Configured correlation rules, filters, and dashboards for real-time monitoring of security events.•Managed log sources from various network devices, servers, and applications, ensuring comprehensive coverage for security monitoring.•DSM creation and log properties extraction for various log sources.•Develop security Use-cases based on MITRE category in IBM QRadar and conducted in-depth log analysis to identify patterns, trends, and anomalies.•Optimized SIEM performance through regular system tuning and upgrades, improving the platform's efficiency and accuracy in threat detection.•Utilized XDR capabilities for proactive threat hunting, identifying, and mitigating advanced persistent threats before they could escalate.•Conducted regular reviews of XDR configurations and policies, adjusting settings to adapt to evolving threat landscapes.•Administered and maintained the Tenable SC platform, conducting regular vulnerability scans using Tenable SC, identifying, and prioritizing security vulnerabilities across the enterprise infrastructure and collaborated with IT teams to provide remediation guidance and track the progress of vulnerability mitigation efforts.•Customized Tenable SC policies to suit the organization's specific security needs, maintained scan schedules to align with business requirements and minimize impact on production systems.•Managed solutions such as Trend Micro Apex one, server security, Trend Micro XDR, McAfee ePO, Symantec SEPM, Symantec EDR and SentinelOne EDR.•Interacting with government SOC (ADDA) team for setting up required steps to manage vulnerabilities, malware threats and reported incidents. •Incident Management based on ITIL best practices.