فضل رحمن, Lead Security Analyst

فضل رحمن

Lead Security Analyst

Netsurion Technologies

البلد
الهند - بنغالورو
التعليم
بكالوريوس, Telecommunication
الخبرات
11 years, 5 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :11 years, 5 أشهر

Lead Security Analyst في Netsurion Technologies
  • الهند - بنغالورو
  • أشغل هذه الوظيفة منذ ديسمبر 2019

- Handle escalated tickets and Perform deep-dive incident analysis

- Handle EventTracker EDR on client environment and Deep Instinct EDR

- Integrating compliance devices with Splunk and EventTracker on frequent basis.

- Working with device administrators to configure the devices to enable/send the logs

- Maintain and improve the SIEM services to identify emerging threats and meet regulatory compliance.

- Monitor and report Vulnerability Assessment scans running on client environment using SAINT

- Conducting Monthly and weekly client review calls using advanced visualization tools like PowerBI and Report Builder.

- Monitoring SIEM logs, Firewall logs, Active Directory log, IDS and IPS logs.

- Creating and working with IOC and dashboards.

- Knowledge of tools like snort, Saint, Excel, Power BI, Dax Studio, Report Builder and Freshdesk as a ticketing tool.

- Analyzing alerts using Splunk Enterprise Security and EventTracker.

- Assisting the clients and Security Analysts with product and security related issues.

Cyber Security Engineer في MST - ATI Electronics
  • المملكة العربية السعودية - جدة
  • أكتوبر 2015 إلى أكتوبر 2019

- Continuous monitoring, analyze security alerts and event information for all approved security feeds to include investigation of incidents using system logs, event correlation between IDS/IPS, firewall and other means of detection.

- To monitor the Status & connectivity of 3000+ Devices with SIEM.

- Handle escalated tickets and Perform deep-dive incident analysis

- Integrating compliance devices with Splunk on frequent basis.

- Working with device administrators to configure the devices to enable/send the logs

- Design and develop innovative methods of automatic event processing to satisfy compliance and operational requirements.

- Maintain and improve the SIEM services to identify emerging threats and meet regulatory compliance.

- Assessing the SIEM, Log Baselines implemented and the SOC Procedures, for finding the gaps.

- Conducting workshops to discuss Use cases and Log baselines with Clients

- Monitoring SIEM logs, Firewall logs, Active Directory logs

- Creating and working with IOC dashboards.

- Knowledge of Process Explorer and Carbon Black

- Analyzing alerts using Splunk Enterprise Security and Qradar

- Malware Analysis

- Email Phishing Analysis

Senior Technical Support Specialist في Convergys - India
  • الهند - بنغالورو
  • أغسطس 2007 إلى يونيو 2010

الخلفية التعليمية

بكالوريوس, Telecommunication
  • في A.P.S College of Engineering (VTU)
  • نوفمبر 2009

Specialties & Skills

Cyber Security
Information Security
Malware Analysis
Security Information Event Management SIEM
CUSTOMER RELATIONS
Phishing Email Analysis
Incident Response
Information Security Tools
Communication Skills
Network Security
IDS/IPS
SOC Analyst
Deep Instinct Endpoint Security

اللغات

العربية
متوسط
الانجليزية
متمرّس
الهندية
متمرّس
الأوردو
متمرّس

التدريب و الشهادات

Deep Instinct Certified Engineer (الشهادة)
تاريخ الدورة:
August 2020
Incident Response (تدريب)
معهد التدريب:
Cybrary
تاريخ الدورة:
September 2019
المدة:
6 ساعات
Information Security (تدريب)
معهد التدريب:
Cybrary
تاريخ الدورة:
September 2019
المدة:
20 ساعة
Splunk Fundamentals (تدريب)
معهد التدريب:
Splunk
تاريخ الدورة:
September 2019
المدة:
12 ساعة
CompTIA Security+ (تدريب)
معهد التدريب:
Udemy
تاريخ الدورة:
August 2019
المدة:
20 ساعة
CCNA (الشهادة)
تاريخ الدورة:
July 2009
صالحة لغاية:
July 2012

الهوايات

  • Travelling and Spending time with my family.