Cyber Security Analyst
CurrentCyber Security AnalystNetwork:Wireshark, Splunk, Snort,Cyber Kill Chain Framework, TCPDump, Nmap, Security Onion, FireEye, Redline, PCAP Analysis, TCP/IP, VERIS, Metasploit Framework, IBM’s QRadar, Nessus. Operating Systems:Windows, Unix/Linux,MAC OS, VMware , Android/IOSVirginia / November 2020 - Present • Follow detailed operational processes and procedures to appropriately analyze, escalate, and assist in remediation of security incidents.• Liaise with the Company's Security Operation Center to respond to emerging incidents in a timely manner.• Perform analysis of log files of Firewall, IPS,IDS, Server and Proxy via Splunk SIEM solution. • Analyze PCAP files for Malware analysis and find details of the infected hosts andwrite IOC on executive summary reports.• Provide analysis and containment of compromised systems and mitigate root causes.• Assist in performing periodic access reviews/inactivity reviews.• Identify, track, and investigate high-priority threat campaigns, malicious actors with the interest, capability and TTPs (Techniques, Tactics and Procedures).• Analyze and review escalated cases until closure. This includes investigating and recommending appropriate corrective actions for cybersecurity incidents.• Perform post-mortem analysis on logs, traffic flows, and phishing activities to identify malicious actors.