Soc Analyst
Current• Investigates phishing emails utilizing email security solution (Proofpoint TAP) and open-source tools such as MX Toolbox to conduct manual analysis• Triages alerts and detections to determine scope, classification, and impact, documenting investigation and recommendations using ticketing systems (The Hive, Jira).• Utilizes Vulnerability Assessment tools (Nessus, Tenable.io, Acunetix) to proactively identify weaknesses and improve security posture.• Provides support in a 24/7 Security Operations Center (SOC), monitoring and analyzing security events using SIEM solutions (Splunk ES, IBM QRadar) to identify potential threats.• Performs incident response on endpoints using EDR/XDR tools (CrowdStrike, SentinelOne) to investigate static and dynamic incidents, determine root cause, and implement mitigation measures.• Analyzes PCAP files using Wireshark to inspect network traffic and data packets, and identify any anomalies or security concerns• Uses MITRE ATT&CK framework to identify threats, risks, vulnerabilities, and classify detection signatures of malicious activities• Collaborates extensively with SOC team, leading SOC shifts, actively monitoring industry trends and threat intelligence feeds for emerging threats and vulnerabilities with potential to impact the monitored environment