
Professional Summary:
. Cyber Security Specialist with 2 years 4 months of comprehensive experience in designing, implementing, and troubleshooting network infrastructure and security protocols.
. Proven expertise lies in Splunk SIEM administration and analysis, adeptly utilizing SPL for intricate data querying and analysis.
. Proficient in an array of industry-standard tools including Splunk, Python, Azure Cloud, CrowdStrike Falcon, SOAR, and Proofpoint.
. Demonstrated capabilities encompass malware analysis, penetration testing, incident response, and the development of service improvement plans.
. Committed to ensuring optimal security measures through continuous adaptation and innovation.
▪Applied basic Splunk knowledge to troubleshoot and resolve operational issues, enhancing system reliability and efficiency.
▪Contributed to the implementation of Splunk alerts and notifications, enhancing proactive incident response capabilities within the project environment.
▪Analyzing and determining threat impact.
▪Categorize the incidents into appropriate categories.
▪Provide recommendation on mitigation of security incidents.
▪Notifying the SOC Remediation/Response Specialist (SRS) to provide resolution steps or workaround,
▪Escalating security incidents per the incident response escalation procedure
▪Following up with remediation groups for closure of open incidents and issues
▪Closing SOC created tickets and tasks after resolution confirmation
▪Identifying attacks or attack pattern and gather information about attackers
▪Generating scheduled and ad-hoc SOC reports(Monthly/Weekly)
▪Verifying the uptime, health, and welfare of all managed or monitored devices
▪Recommending new alerts/correlation rules and reports
▪New use case recommendation for SOAR environment
▪Adherence to SOC SLAs, communication protocols and policies
▪Update Threat Intelligence data.
▪Trending of Security events and incidents, Monitoring of Dashboards.
▪Demonstrated ability to leverage Splunk search processing language (SPL) for querying, filtering, and analyzing machine-generated data.
SOC Analyst L2 Proficiency:Expertise in SIEM, SOAR, Splunk, Microsoft Azure, Crowdstrike, Email security, and PythonSplunk Proficiency:Proficient in Splunk for log management, analysis, and threat detectionCapable of leveraging Splunk's search processing language (SPL) for advanced data querying and analysisCrowdstrike Expertise:Experienced in Crowdstrike for endpoint security, threat detection, and responseProofpoint Defender Skills:Skilled in Proofpoint Defender for email security, threat intelligence, and phishing protectionIncident Response and Threat Hunting:Experienced in conducting incident response and threat hunting activities using Splunk and CrowdstrikeProficient in analyzing and interpreting security events and alerts generated by Splunk, Crowdstrike, and Proofpoint DefenderData Analysis and Insights:Skilled in generating actionable insights and recommendations based on security data analysis within Splunk and other security platforms
Splunk Core Certified Power User