Over 3 years of experience in Incident Response and Threat Hunting, utilizing SIEM tools such as Splunk and Sentinel. Expertise in EDR solutions, Malware Analysis, and Endpoint Security, with a strong emphasis on log analysis and email security. Additional 4 years in Desktop Support, focusing on system troubleshooting and diagnostics.
Executed alert monitoring and incident response using Azure Sentinel SIEM.
Analyzed threats from firewalls, endpoints, servers, and IDS/IPS to identify true and false positives.
Conducted SIEM event analysis and manual correlation to pinpoint infection vectors and root causes.
Utilized Azure KQL for log analysis from external data connectors, enhancing alert investigation.
Provided ongoing monitoring, triage, and response to automated security alerts using various security tools.
Managed endpoint tools like CrowdStrike and Microsoft Defender to strengthen endpoint security.
Facilitated weekly client meetings to report SOC progress and security trends.
Evaluated and documented malicious activity across all end devices.
Escalated incidents and inquiries to appropriate support groups for timely resolution.
Managed Trade Tiger Application and Sharekhan Education Website to ensure optimal performance.
Assisted end users by resolving computing issues and fulfilling application support requests.
Installed, trained, maintained, troubleshot, and repaired all desktop hardware and software.
Maintained day-to-day relationships with third-party vendors for service delivery and support.
Executed second-level troubleshooting and resolution of desktop and mobility technology problems.
Resolved tickets and fulfilled employee requests for application and system support.
Delivered L1 and L2 IT support, adhering to severity matrix within SLA.
Utilized SCCM client management tool to deploy applications across entire domain.
Managed installation, troubleshooting, and overall application support.
Facilitated meetings using WebEx, Zoom, and Inter-call platforms.
Coordinated with top-level management while strictly following Firm Escalation matrix.
SIEM tools: Azure Sentinel and Splunk
Endpoint security solutions: Microsoft Defender, Symantec, CrowdStrike
Email security platforms: Mimecast, Microsoft O365, ProofPoint
Vulnerability management tools: Qualys, Nessus
Ticketing systems: ServiceNow and CA Service Desk