Over all 4.2 Years of experience in information technology and 3.2 Years of experience across SIEM tools, Intrusion Prevention System, Vulnerabilities and remediation, Antimalware and firewall.
optimization and troubleshooting of network security devices.
Familiarity with firewall implementation and SOC monitoring with best practices.
Familiarity with cyber security regulations, including cyber security standards and implementing best practices.
Agile in investigating security threats such as Malware Outbreaks, DDOS, OWASP T-10
Overview
4
4
years of professional experience
1
1
Certification
Work History
Information Security Analyst
Alten Calsoft Labs Private Limited
Mumbai
02.2023 - Current
Perform Security Incident Event Management (SIEM) console monitoring and correlation
Optimizing, managing and monitoring real-time events from devices like firewalls, web proxy, antivirus vendors, DCs using ArcSight , QRadar and DLP data loss prevention
Oversee and ensure P1 and P2 incidents are handled according to operational procedures
Document areas of improvement through after-action reports and work with necessary parties to resolve any findings
Detecting potential data breaches/data ex-filtration transmissions and prevents them by monitoring
Designated systems detect and prevent unauthorized attempts to copy or send sensitive data, intentionally or unintentionally, mainly by personnel who are authorized to access the sensitive information
Authentication Manager includes an administrative user interface called the Security Console
For example, you use the Security Console to: Add and manage users and user groups
RSA Authentication Manager from RSA Security is a multifactor authentication software tool that adds additional security measures (via smartphones and biometrics) to standard username and password logins for a number of services and servers
RSA provides both SecurID hardware and software tokens
Initially, the Security Console and Operations Console both use the user name and password that you specified during Quick Setup
If you change the user name or password for either Console, the user name and password for the other Console remains unchanged
Work closely with business units to ensure that they know how to feed data into SIEM tools to create network hierarchy and classify Log Sources within SIEM
Creation of reports, filters, active channels, queries, dashboard and fine-tuning rules in ArcSight for monitoring purpose
Experienced in client communication on potential threats and suitable recommendations
Fetching timely reports from the arc sight console and updating to customer
Experienced in creating active channels, applying filter, creating filter in the Arc sight Console
Maintained 100% response SLA throughout my time in my experience
Experienced in managing cloud SOC and On-Site SOC
Drive monitoring of security events using a SIEM and other feeds, looking for significant events, and processing reports of unexpected network activity
Executed regular configuration and troubleshooting of Checkpoint Firewall through packet captures and analysis with TCP dump etc
Support network level firewalls, internal security systems, cloud and network infrastructure
Creation/Review of Security Policies, Standards and Procedures
Analysing the security advisories for taking preventing measure for vulnerabilities and malwares
Escalating the security incidents based on the client's SLA and providing meaningful information related to security incidents by doing in-depth analysis of event payload, providing recommendations regarding security incidents mitigation which in turn makes the customer business safe and secure
Co-ordinate extensively with networking teams to maintain and establish communication to remote QRadar Collectors/Processors
Clear the risk-based authentication (RBA) device history to unregister devices
Responding to various security alerts for various client and scanning for vulnerabilities using tools like NESSUS
Configure security questions for identity confirmation
Manage their RSA SecurID PIN
Security questions cannot be used as a primary authentication method to access the Self-Service Console
Primary methods are RSA Password, LDAP Password, On-Demand Authentication, and SecurID
Responsible to preparing the root cause analysis reports based on the analysis
Analyzing daily, weekly and monthly reports
Project
IT Security Analyst
Tata Communications Limited
Pune
06.2019 - 08.2021
Helped standardize and implement the scheduled maintenance plan documentation process
Monitored system performance and diagnosed software/hardware problems
Document and track issues via a ticketing system
Ensured full and incremental data backups were successful
Performed data restore for users as needed
Responsible for applying security updates and patches on servers, desktops, and laptops
Configured, troubleshot, and maintained Windows 2003 and 2008 Servers.
Education
B.Com of Technology - undefined
SRK Degree College
Intermediate - undefined
MASTERMINDS Junior College
S.S.C - undefined
Board of Secondary education, TULIPS CONCEPT SCHOOL
Timeline
Information Security Analyst
Alten Calsoft Labs Private Limited
02.2023 - Current
IT Security Analyst
Tata Communications Limited
06.2019 - 08.2021
B.Com of Technology - undefined
SRK Degree College
Intermediate - undefined
MASTERMINDS Junior College
S.S.C - undefined
Board of Secondary education, TULIPS CONCEPT SCHOOL
Skills
RSA, QRadar, Arc Sight, and McAfee Incident responseundefined