Cyber Security Engineer
CurrentScanned the servers using Qualys scanner & reported the vulnerabilities to the appropriate teams for remediation.Created Qualys scan profiles for different project requirements.Generated customized Qualys reporting templates to explain the remediation status to the tower teams.Monitoring SIEM for any security Threats and Investigating the events and working on L2 tickets.Creating Dashboards, Active Channels, filters and Data monitors as per the requirement on SplunkManaging EDR Console. SentinelOne & CylancePerforming Ad-hoc scans when a Vulnerability is identified, OR a new system is added to the network with Nexpose.Conducting Vulnerability scans on Internally developed web apps using IBM AppScanCollaborating with stake holders in patching the vulnerabilities.Monitoring Sourcefire for any security Threats, Investigating the threat eventsWorking on security Incidents reported by users and building Incident reportsParticipated in Internal Phishing exercise using PhishMe.Developed Threat Hunting program and trained teammates in performing threat hunting campaigns based on NSA&FBI reports and OSINT data.Accountable for, Threat and part of Vulnerability Management, incident management and EDR monitoring.Incident analysis, responses and remediation using Azure Sentinel SIEMCarrying out vulnerability assessment, network scanningPerforming comprehensive investigations of security breaches.Participating in Internal Penetration testing using Kali Linux.Worked with multiple clients for implementing Vulnerability Management using Nexpose and NessusMonitoring SIEM, IPS/IDS and investigating the offenses.Monitoring McAfee ePolicy Orchestrator and responding alertsResearching on latest vulnerabilities and analyzing their consequences on the organizationResponsible for creating and troubleshooting Windows logon accounts via Active DirectoryManaging MDM tools Airwatch and Working on day-to-day tickets with high customer satisfaction levels