
Dynamic and result oriented XSOAR engineer, security analyst and Team lead in Information Security domain with 8 years of experience in cybersecurity and total experience of 11 years, having good experience in XSOAR,SIEM and Symantec DLP in monitoring and analysis of malicious threats using SIEM tools like RSA with strong capability to analyze and respond to Intrusion attempts.
● Using RSA Netwitness SIEM solution and other security tools to monitor any security threats in network.
● Advising in fine tune correlation rules to cover broad spectrum of security incidents and reduce false positives
● Creation of dashboards, Lists Parsers, reports
● Investigating incidents, remediation, tracking and follow-up for incident closure with concerned teams, stakeholders
● Checking the EPS consumption on daily basis for any event drops.
● Regular inspection of health check related to Log Sources and adding new devices for better monitoring coverage through SIEM tool.
● Working in Security Operation Centre (24x7), monitoring of SOC events, detecting, and preventing Intrusion attempt.
● Experience on performing log analysis and analyzing crucial alerts at immediate basis.
● Experience in understanding logs of various network devices (Routers, IDS/IPS, Firewall), operating system (Windows).
● Investigating and reporting on daily scan activities.
● Analysing and report detailed information related to threat hunting.
● Worked in Antimoney laundering and KYC.
Automation engineer(Paloalto XSAOR)
undefinedXSOAR engineer