We provide IT Staff Augmentation Services!

Enterprise Soc Analyst Resume

3.00/5 (Submit Your Rating)

Rockville, MD

OBJECTIVE:

CompTIA Security + certified professional with 8 years of IT experience seeking employment as a Security Analyst to use my passion, skills and experience to provide effective cybersecurity support and excellent customer services.

SUMMARY:

  • High level of attention to detail, strong leadership skill, and ability to multitask.
  • Dependable and have many years of excellent positive track record such as outstanding annual performance review conducted by supervisors.
  • Knowledge of ITIL principles and ability to apply its concept to timely resolve complex issues while documenting change management with detail.
  • Knowledge of OSI 7 model and TCP/IP 4 and secure network architecture with defense - in-depth concept model.
  • Knowledge of IDS/IPS for both host and network and secure firewall ACL configuration and log analysis with SIEM solution.
  • Knowledge of TCP 3-way handshake process and packet analyzer tools such as tcpdump and Wireshark.
  • Knowledge of common behaviors of attacks and different threat actors.
  • Knowledge of security incident handling best practice and forensics procedure such as securing evidence and maintaining chains of custody document for compliance.
  • Experience with vulnerability assessment cycle and POA&M management.
  • Knowledge of CRM and change management tools (BMC Remedy, OTRS, Atlassian JIRA and IBM ClearQuest)
  • Knowledge of using system, network and security monitoring tools (ManageEngine IT360 & OpManager, Oracle Enterprise Manager, NAGIOS, Kenna, Cisco AMP, AlienVault and Splunk)

EXPERIENCE:

Enterprise SOC Analyst

Confidential, Rockville, MD

Responsibilities:

  • Performed 24 hour SOC operations and performed duties to include IDS event monitoring and analysis, security incident handling, incident reporting, and threat analysis.
  • Proactively analyzed data from variety of sources such as full packet capture, security device, logs and data collected from end-points using tools such as SCCM, Cisco AMP and Nessus.
  • Proactively hunted for malicious or anomalous activity across the enterprise, using both existing tools and experimenting with new detection techniques.
  • Documented detected vulnerabilities from security scans in a POA&M (Plan of Action & Milestone) and followed recommended remediation to secure valuable enterprise assets.
  • Assisted in conducting advanced computer and network tests relating to many different forms of malware analysis, computer intrusion, theft of information, and denial of service.
  • Drafted formal and informal reports with details of the malware, advanced, capabilities, identification parameters, and mitigation & prevention strategies.
  • Assisted with education of enterprise end-users by drafting basic security information documents containing awareness training and common examples including social engineering and phishing techniques.
  • Assisted Confidential (Cybersecurity and Emergency Response) team with gathering, isolating, and analyzing digital evidence related to a security breach.

NOC Engineer Lead

Confidential, Rockville, MD

Responsibilities:

  • Perform 24/7 monitoring service for MMIS(Medicaid Management Informational System) clients providing reports and escalations to ensure operational uptime for continual operation.
  • Provide solutions and problem resolution to clients, with a strong commitment and drive towards customer service; AND
  • Provide cyber security support, such as risk detection and assessment of vulnerabilities using various tools and IDS such as SCCM, AMP, Nessus, and AlienVault.
  • Detect and investigate network issues such as DNS forwarding misconfiguration, CNAME to NS record missing and blocked port for UDP/TCP connections.
  • Take ownership of an active incident and provide support to a client until resolution with strict accordance to time within SLA. (Service Level Agreement)
  • Work closely with other IT infrastructure teams to deliver top-quality solution to resolve incidents in timely manner.
  • Serve as a point of contact for all monitoring initiatives development and implementation
  • Assisted senior architect and enterprise engineer with conversion from traditional IT infrastructure to Cloud solution by participating in capacity planning and providing real-time metric to better determine accurate model and save cost.
  • Present technical and non-technical information and documentation to colleagues and supervisor to achieve best up-to-date practice.

IMDAS Helpdesk Engineer

Confidential, Rockville, MD

Responsibilities:

  • Provided Tier one helpdesk support to end-users of Intelligent Mail Device electronic assets for USPS such as workstation, handheld scanner, mount, and uninterruptable power supply to meet resolution.
  • Investigated reported issues and walked customers through scripted service protocols to triage and resolve minor issues.
  • Escalated service outage to relevant vendor and provided technical information to vendor to expedite recovery.
  • Served as point of contact with vendors regarding defective equipment replacement and drive to ensure expedited process to lessen operational outage.
  • Assisted senior technical director with implementation and testing of disaster recovery site and its function to be compliant with updated project requirement.
  • Achieved excellent performance and received recognition by organization for resolving many incidents effectively to ensure customer satisfaction.
  • Created a documentation for new duty and maintained documentation for all procedures to be current and compliant to policy.

Operation Support Technician

Confidential, Gaithersburg, MD

Responsibilities:

  • Provided operation support to end-users at office premises performing duties such as software installation and printer installation.
  • Performed regular maintenance task such as cleaning temp folder, resetting end-user’s password and replacing malfunctioning peripherals.
  • Assisted facility director by providing advise and testing for infrastructure setup.
  • Answered customer questions related to software errors and exceptions and provided resolution; AND
  • Contacted vendor helpdesk support to report incidents that require vendor support and followed up to resolution.
  • Provided the facility director with new ideas, changes, and improvements to simplify the infrastructure.
  • Created a documentation for end-users to serve as manuals for their tasks and updating documentation to keep it up-to-date.

Computer Maintenance Intern

Confidential, Rockville, MD

Responsibilities:

  • Assisted end-users with providing solution for computer related issues such as recovering deleted files, recovery from Confidential blue-screen error, and fixing jammed laser printers.
  • Distinguished inoperable and expired computer peripherals and sort them for recycles.
  • Disassembled computer parts from retired workstations and salvage parts for future use.
  • Assisted computer maintenance teacher with deployment of new software and updates for Confidential and Confidential workstations.
  • Performed weekly backup using magnetic tape and collect backed up tape to present it to computer maintenance teacher.
  • Provided computer maintenance teacher with metric reports for workstation resource usage when requested.
  • Assisted computer maintenance teacher with production of CAT4 ethernet cables by cutting and crimping cables.

We'd love your feedback!