Overall 5.4 years of experience into Information Security as Security Analyst (SOC)
Good understanding of security solutions like Anti-virus, DLP, Proxy, Firewall filtering/monitoring, IPS, Email Security, EPO, WAF etc.
Hands on experience with QRadar ,Azure Sentinel and Splunk SIEM tool for logs monitoring and analysis, Service now ticketing tool.
Good knowledge on networking concepts including OSI layers, subnet, TCP/IP, ports, DNS, DHCP, firewall monitoring, content filtering, check point etc.
Overview
6
6
years of professional experience
1
1
Certification
Work History
Associate
Cognizant
Hyderabad
04.2022 - 06.2024
Served as Analyst in SOC operations for real-time monitoring, analyzing logs from various security/Industrial appliances.
Administrating various incidents/security alerts triggered in SIEM tool.
Carrying out log monitoring and incident analysis for various devices such as Firewalls, IDS, IPS, database, web servers and so forth.
Security event analysis and intrusion detection by review and analysis of events generated by various components including IDS/IPS, firewalls, Routers, DB, OS and various types of security devices.
Knowledge of Installation, Configuration and upgradation of various connectors, and its troubleshooting.
Work closely with business units to ensure that they know what and how to feed data into Qradar or Splunk and to create network hierarchy, classify Log Sources within the QradarSplunk SIEM.
Assocaite
IBM
Bengaluru
03.2020 - 12.2021
Monitoring the customer network using SIEM tool– IBM QRadar, Splunk, AZ Sentinel
Performing Real-Time Monitoring, Investigation, Analysis, Reporting and Escalations of Security Events from multiple log sources
Maintain keen understanding of evolving internet threats to ensure the security of client networks
Contacting the customers directly in case of high priority incidents and helping the customer in the process of mitigating the attacks
Understanding the incident based on to determine whether it’s false or true positive
Troubleshooting SIEM dashboard issues when there are no reports getting generated or no data available and Identify, investigate, or resolve security breaches and incidents.
Creating Dashboard on QRadar or Splunk to analyze the Data
Senior Associate Consultant
Wipro
Hyderabad
09.2018 - 03.2020
Troubleshooting basic errors identified in Qradar and fixing those errors.
Support security incident response processes in the event of a security breach by providing incident reporting.
Handling multiple customers globally analyzing the customer networks for potential security attacks.
Cross checking the scanned files which we have received from the Helpdesk Team for the recommendation we have given.
Configuring RADIUS or TACACS+ authentication on Cisco ASA firewalls
Working experience on troubleshooting Cisco VPNs both Site-to-Site and Remote Access