Security Operations Center Analyst
Current• Working in a 24x7 Security Operations Center • Monitoring the customer network using Splunk SIEM • Act as first level support for all Security Issues • Performing Real-Time Monitoring, Investigation, Analysis, Reporting and Escalations of Security Events from Multiple log sources. • Raising true positive incidents to the respective team for further action • Creating tickets on service now and assigning it to the respective team and taking the follow-up until closer • Escalating the security incidents based on the client's SLA and providing meaningful information related to security incidents by doing in-depth analysis of event payload, providing recommendations regarding security incidents mitigation which in turn makes the customer business safe and secure. • Contacting the customers directly in case of high priority incidents and helping the customer in the process of mitigating the attacks. • Work closely with business units to ensure that they know what and how to feed data into the SIEM • Investigate malicious phishing emails, domains, and IPs using Open-Source tools and recommend proper blocking based on analysis • Good knowledge of Splunk Distributed cluster Architecture • Detail knowledge of the working functionality of various components of Splunk such as Indexer, Search head, Heavy forwarder, deployment server etc. • Experience in onboarding of data sources with Splunk such as Windows, Linux, Fortinet Firewall etc. • Installing Splunk apps and Addon on the Splunk • Experience in installation of Universal forwarder on the servers for logs collection • Troubleshooting in-case any device is not reporting to the Splunk • Knowledge of Creating dashboard, Reports in Splunk • Knowledge and experience in creating Correlation Searches/Rules in Splunk • Working experience searching and Reporting in Splunk having good SPL knowledge