As a Senior SOC Analyst with over five years of dedicated experience, I specialize in defending enterprise environments using the IBM QRadar SIEM platform. My expertise lies in advanced threat detection, security content engineering, and process automation. I am passionate about leveraging data to proactively hunt for threats and continuously improve an organization's security posture.
Core Competencies & Experience
1. Advanced Threat Analysis & Investigation:
I have extensive, hands-on experience leading complex offense investigations, adhering to structured SOPs from initial triage to resolution.
My daily work performs in-depth threat hunting and reconstruct attack timelines.
2. Security Content Engineering:
I specialize in optimizing SIEM performance by meticulously tuning rules to reduce false positives.
I develop and deploy new detection use cases mapped to the MITRE ATT&CK framework, enhancing our defensive capabilities against modern threats like C2 communication (T1071) and Brute Force attacks (T1110).
3. SIEM Platform Operations & Maintenance:
My responsibilities include overseeing the health and stability of the QRadar-SIEM deployment, and I have successfully managed multiple version upgrades and critical patch installations.
I manage the full lifecycle of log sources, from onboarding new systems like Palo Alto firewalls to troubleshooting DSM parsers to ensure data integrity.
4. Automation & SOAR:
To improve SOC efficiency, I develop scripts to automate routine tasks, such as offense data retrieval.
I actively contribute to developing and testing Ansible playbooks for automated response actions, including the automatic blocking of malicious IPs on firewalls.