Senior Soc Analyst at Cyberproof (A UST Company) (2023-03 – Present)
- Performed detailed security incident investigations and root cause analysis by analysing and correlating logs and alerts from diverse sources to detect patterns, anomalies, and potential threats.
- Advanced thread detection and analysis of security incidents, as well as reporting cybersecurity incidents to the L3 analyst or directly to the client
- Performing a service quality review on deliverables produced by the SOC L1 analyst. This includes reviewing incident reports, threat assessment, and other security related documentation to ensure that they are accurate and meet the required standards
- Improving the overall detection coverage of the SOC team. This includes suggesting new rules and techniques for threat detection, as well as tuning existing rules to improve their effectiveness
- Follow detailed processes and procedures to analyse, escalate, and assist in the remediation of critical security incidents
- Utilize ticketing systems to manage and respond to Incident Requests (IR's) promptly.
- Provide timely and detailed responses to client inquiries via phone, email, or ticketing system
- Participate in client calls to discuss security posture, incident reports, and strategic recommendations
SOC Analyst at Cyberproof (A UST Company) (2020-03 – 2022-12)
- Worked in a 24x7 Security Operations Centre, Communicate the severity of the threat and recommendations for remediation to the customer and other cyber security personnel through written and verbal media
- Worked in Azure Sentinel, Splunk, IBM Qradar, CrowdStrike Falcon EDR, Trend Micro, Microsoft Defender ATP and Proofpoint
- Worked on the incident response activities like malware analysis, phishing analysis, network and user behavior detections
- Create Daily, Weekly and Monthly reports, as per client's requirements
- Investigate Emails, syslog, EDR, firewall, IDS, IPS, WAF, proxy or DNS and AD logs with help of Open-Source tools and provide proper mitigation recommendations
SOC Analyst at NTT (2019-05 – 2020-03)
- Monitor RSA Security Analytic dashboards to keep track of real-time security events and health of SIEM devices
- Monitors Security Analytics dashboards to keep track of real time security events and health of SIEM devices
- Monitoring malicious IPs and domains Activities over the client's network and alert relevant teams to take preventive actions
- Incident handling, analysis and response using RSA Netwitness and RSA Archer.
- Creating reports, and dashboards in Security Analytic
- Creating Real-time alert as per client requirement
- Hauling Ad hoc report for various event sources and, customized reports, and scheduled reports as per requirements
- Follow up with RSA technical support team for system related issues
- Identify and discuss relevant security alerts with senior security analyst & Team
IT Administrator at Liber Engineering & Construction Co. W.L.L, Kuwait (2018-01 – 2018-12)
- Install network and computer system
- To upgrade hardware and software program
- Manage data backup and retrieval processes
- Troubleshoot problems with systems and programs
- Work in Active Directory
- Manage user accounts
- Developed organizational units in Active Directory and manage user security with group policies
- AD Backup
- Talking staff or clients through a series of actions, either face-to-face or over the telephone, to help set up systems or resolve issues
IT Support at ELMEC Engineering Company W.L.L, Kuwait (2016-10 – 2017-12)
- Installing and configuring computer, hardware, software, systems, network and printers
- Setting up accounts for staff, ensuring that they know how to log-in
- Providing IT assistance to staff and customers
- Monitoring hardware, software, and system performance metrics
- Rapidly establishing a good working relationship with customers and other professionals
- Conducting electrical safety checks on computer equipment
- Providing support, including procedural documentation and relevant reports
- Supporting the roll-out of new applications
Network Support at Fast track call cab (P) ltd (2015-07 – 2016-08)
- Installing and configuring computer hardware, Operating systems, Network storage, Network printer, Switch, Router, Server and Applications
- Monitoring and maintaining computer systems and networks
- Troubleshooting system and network problems and diagnosing and solving hardware or software faults
- Replacing parts as required
- Following diagrams and written instructions to repair a fault or set up a system
- Setting up new users' accounts and profiles and dealing with password issues