Cybersecurity Analyst
Current●Worked in a 24x7 Security Operations Center●Monitoring the customer network using Splunk SIEM●Act as first level support for all Security Issues●Analyzing Realtime security incidents and checking whether its true positive or false positive●Performing Real-Time Monitoring, Investigation, Analysis, Reporting and Escalations of Security Events from Multiple log sources.●Creating tickets on service now, Zendesk and assigning it to the respective team and taking the follow-up until closer ●Escalating the security incidents based on the client's SLA and providing meaningful information related to security incidents by doing in-depth analysis of event payload, providing recommendations regarding security incidents mitigation which in turn makes the customer business safe and secure.●Contacting the customers directly in case of high priority incidents and helping the customer in the process of mitigating the attacks.●Determine the scope of security incident and its potential impact to Client network; recommend steps to handle the security incident with all information and supporting evidence of security events.●Investigate malicious phishing emails, domains, and IPs using Open-Source tools and recommend proper blocking based on analysis