Event Analyst
Macomb Michigan
Provide Detection on the Global General Motors Network to find malicious malware, and ransomware. Monitored, Detect and evaluated the packets on the network using a variety of tools to determine if an information security event violation occurred. When a incident was identified it was escalated to the appropriate Teams to ensure the affected assets on the network were contained and remediated.•Provide real-time monitors Security Information and Event Management (SIEM) systems(HP Arcsight ESM), and threat intelligence reports(Cisco ThreatGrid) to detect and research security-related alerts and events(Squil).•Research various security events using research tools and threat intelligence to determine when an incident has occurred•Evaluated malware, and ransomware characteristics and recognize known characteristics in the wild•Analyze “sweeps” the IT environment looking for indicators of compromise•Follow detailed operational process and procedures to appropriately triage, analyze, and escalate critical information security events.•Consume Threat intelligence to proactively detect threats to the GM IT infrastructure•Created tactical, ad hoc scripts using python to supplement existing tool base as needed•Used network security monitoring tools (IDS events, Flow tracking, Packet loggers, etc.) to properly analyze and respond to information security events.•Escalated to the appropriate Teams such as Network, Outlook, Incident Handler •Used forensics applications and other host based tools (file, memory, and disk analyzers)•Wrote scripts in Python to create automated tools to help detect threats quickly to contain threats on the network•Provided written and verbal communication skills •Worked in a Team environment