Security Analyst
Current• Lead security monitoring and incident response efforts, utilizing tools like Azure Sentinel, Splunk, and SentinelOne to detect and mitigate threats.• Conducted in-depth investigations into advanced security incidents, including targeted attacks and insider threats, using CrowdStrike and FireEye.• Enhanced SIEM capabilities by creating and tuning custom detection rules in Splunk and IBM QRadar, improving the accuracy and efficiency of alerts.• Performed regular threat-hunting activities with the use of FireEye and CrowdStrike, identifying and neutralizing potential threats before they could cause harm.• Worked extensively with cloud security tools like Microsoft Defender for Cloud and AWS Security Hub to secure multi-cloud environments.• Conducted vulnerability assessments using Tenable.io, collaborating with teams to prioritize and remediate identified risks.• Automated routine security tasks through scripting in Python and PowerShell, reducing manual effort and improving response times.• Integrated new security tools such as Zscaler and Fortinet Security Fabric into the existing SOC environment, enhancing overall security posture.• Managed incident response for phishing attacks, leveraging email analysis tools and strengthening phishing detection rules.• Performed continuous monitoring and analysis of network traffic using tools like Wireshark and tcpdump to detect anomalies and prevent data breaches.