Cyber Security Analyst
Current•Manage 24X7 operations at SOC, including event monitoring which includes incident detection, tracking and analyzing on real time basis, with follow-up on any suspicious activity.•Identify and escalate confirmed incidents and their impact on the network and escalate them with all the information, evidence, and coordinate with multiple functional teams to mitigate the threat.•Directly contacting with customers during high-priority incidents, guiding them through the mitigation process to prevent further cyber threats.•Circulate the latest threat landscape on vulnerabilities, threat actors, CVEs, and IOCs to stakeholders. Ensure that indicators are added to the blacklist and devices are patched.•Preparing SOP's and knowledge resources for the team members.•Handle customer requests, such as historical log searches and fulfilling audit requirements, to maintain compliance and support client inquiries.•Generate and track tickets for suspicious incidents until closure, ensuring comprehensive incident management.•Prepare daily, weekly, and monthly security incident reports for record-keeping and future investigations.•Refine SIEM tool alerts by finetuning false positives and performing log stoppage activities to enhance alert accuracy.•Sharing Logger and ESM daily reports to SIEM Admin.•Share Logger and ESM daily reports with the SIEM Admin to maintain a consistent and updated threat landscape.•Prepare presentations for daily stand-up calls, keeping stakeholders informed and aligned with SOC operations.