Experienced Cybersecurity Analyst with 5 years of expertise in endpoint security, network security, cloud security, and vulnerability assessments. Proficient in utilizing advanced tools including SASE, SIEM, DLP, EDR, AV, and IPS for effective protection against cyber threats. Seeking to leverage extensive knowledge and experience to add value to a dynamic cybersecurity team.
Overview
5
5
years of professional experience
1
1
Certification
Work History
Cyber Security Engineer
Indus Valley Partners Pvt Ltd
12.2021 - Current
Configure and implement Trellix IPS for network security and maintenance of security infrastructure with objective of detecting, preventing and managing network intrusions
Deploy and manage Fortinet SASE to secure endpoints by enforcing zero-trust security policies
Utilize Fortinet Fortianalyzer for centralized log management and security analytics to detect anomalies and prevent threats
Manage Trellix EPO and EDR for centralized endpoint security, policy enforcement, monitoring, and threat analysis
Implement and maintain SentinelOne EDR for next-generation endpoint protection, AI-driven threat detection, and automated remediation and work on the incident alert
Administer RSA SIEM solutions to enhance threat detection and response by collecting, analyzing, and correlating security logs. Optimize correlation rules to improve detection accuracy and reduce false positives
Configure and enforce MS Intune policies for device compliance, mobile device management (MDM), and endpoint security enforcement
Develop and implement Azure Conditional Access Policies to enforce secure access control and deploy Microsoft Defender to enhance endpoint security and threat protection
Perform vulnerability assessments and management for on-prem servers, AWS servers, and network devices using Nessus, OpenVAS, and ManageEngine
Conduct attack and simulation , dark web assessments to identify potential security risks and data exposures
Perform daily health checks , security reporting, and troubleshooting for security tools
Work on security product license renewal and procurement of new security products to enhance cybersecurity posture
Work on the DDoS alerts and take appropriate action as needed
Integrate AWS Security tools such as CloudTrail, GuardDuty, and VPC Flow Logs into SIEM, enhancing real-time alerting capabilities and achieving a 30% faster threat detection and response rate
Manage and implement Trellix Data Loss Prevention (DLP) and Trellix Drive Encryption policies to protect sensitive data, enforce compliance, and prevent unauthorized data transfers across endpoints, networks, and cloud environments
Participate in cybersecurity audits, including ISO 27001 and SOC 2 , by ensuring compliance with security controls, providing evidence, and supporting risk assessments
Basic knowledge of Fortinet Firewall and understanding of network security protocols like TCP/UDP
IT Engineer
Future Soft Solution Pvt Ltd
11.2019 - 11.2021
Working on McAfee EPO to monitor endpoint security alerts and Compliance
Diagnose and troubleshoot end user application issues and provide appropriate solutions
Manage McAfee ENS deployment and agent installations, ensuring comprehensive coverage across all systems for optimal security and compliance
Ensure and maintain over 95% compliance for AMCore/DAT updates across all systems, strengthening endpoint security and threat prevention
Perform actions on end user systems behalf of malware alerts
Troubleshoot and resolve McAfee DLP issues related to USB access, ensuring compliance with security policies while maintaining operational efficiency
Ensure and maintain system compliance for Windows, AMCore, and other security updates, ensuring adherence to organizational security policies and standards
Working knowledge of Windows operating systems, networks and network security concepts and tools
Experience using ITSM Ticketing tools (e.g Service Now , Remedy) to manage and track incidents