Information Security Analyst (L-2) - Rewterz Information Security - Karachi, Pakistan
(2024-01 - 2025-06)
Project: UBL, FG, NiFT, NBP Funds, HBM
- Conducted proactive threat hunting using Event Search functionality to identify indicators of compromise (IOCs) and anomalous behaviors within event logs.
- Investigated DNS, URLs, IPs, and File Hashes provided by the Threat Intelligence Team to detect and respond to potential threats.
- Leveraged KQL to perform detailed searches on security events, designing interactive dashboards to visualize security data and trends for real-time monitoring within Microsoft Defender EDR.
- Developed and implemented security rules based on defined use cases on SIEM, optimizing and refining them to improve accuracy and minimize false positives.
- Aligned Use Cases on SIEM with the MITRE ATT&CK framework for comprehensive coverage of known adversarial tactics, techniques, and procedures (TTPs).
- Performed assessments to identify and address gaps in log sources on SIEM, ensuring comprehensive and continuous monitoring of the security environment.
- Leverage WAF (Web Application Firewall) logs in SIEM to detect suspicious activities within the organization.
- Configured tailored watchlists within the EDR platform to identify and flag anomalous behaviors, IOCs, and potential security threats in real-time.
- Executed remediation actions using Real-Time Response capabilities to mitigate threats on affected endpoints.
- Create custom playbooks in SOAR to automate the process of blocking incident artifacts based on organization requirements.
- Employed Regular Expression on SIEM to extract specific fields and data points from log payloads for further analysis and correlation.
- Followed the organization's predefined escalation matrix to prioritize, escalate, and resolve security incidents timely.
Information Security Analyst (L-1) - Rewterz Information Security - Karachi, Pakistan
(2023-07 - 2024-01)
Project: National Bank of Pakistan, UBL
- Monitored and reviewed security alerts and incidents using SIEM and EDR platforms to identify potential threats and vulnerabilities.
- Conducted thorough investigations of security alerts to assess the nature, impact, and response actions, classifying incidents as true positives or false positives.
- Managed the blocking of Indicators of Compromise (IOCs) to prevent malicious activities and mitigate security risks.
- Analyzed network traffic and security events to detect anomalies, suspicious activities, and potential breaches.
- Performed continuous surveillance of critical infrastructure (servers, firewalls, domain controllers) to ensure operational and security integrity.
- Collected, documented, and tracked incident data, providing relevant evidence to assist Tier 2 Analysts in escalation and resolution processes.
- Prioritized incidents based on severity, potential impact on services, and user environment to ensure timely responses.
- Developed and maintained custom dashboards to visualize security metrics, event data, and threat intelligence for real-time monitoring.
- Assisted in the escalation of unresolved incidents to Tier 2 Analysts and relevant departments, ensuring proper response times and actions.
- Collaborated with cross-functional teams to ensure effective resolution and documentation of security incidents.
- Contributed to incident reporting and helped prepare statistics and summaries of incidents resolved or pending.