Sr. Cyber Security Analyst, Tier 3
Current● Worked in a SOC team environment and performed Tier III cybersecurity incident response duties including responding to Intrusion Detection System (IDS) alerts in multiple SIEMs, and analyzing network, host, and user logs (e.g., pcap, event logs, authentication logs). ● Worked with ArcSight ESM, Elastic, Splunk Phantom/SOAR, RSA NetWitness, FireEye, Firepower, Microsoft ATA, Carbon Black, McAfee ePO, Microsoft ATA, Proofpoint, Palo Alto Threat Vault/Wildfire, AWS GuardDuty, Azure Sentinel, and ServiceNow applications daily. Trained new analysts regularly. Performed Shift Lead duties.● Prioritizing and differentiating between potential intrusion attempts and false alarms. Suggesting IDS rule tunings within Snort, Yara, Sigma, and vendor-specific rules. Performed threat hunting as needed. Worked on high priority cyber security incidents and projects. Developed analyst SOPs and playbooks for SOAR.