SUMMARY Experienced IT professional with a strong focus on Information Security. 4 years of Information Security experience along with 8 years of client interaction experience.
| WORK EXPERIENCE |
- Work in a Security Operations Center SOC environment supporting internal networks for MSP subscribers
- Hunt, uncover, and analyze zero day threats/malware events
- Full packet analysis and identify malware infection vectors, traversal and behaviour
- Investigate and decision alerts generated by IPS and correlate events via SIEM with log data, netflow data and both known and unknown IOC's.
- Tune and write rules for SIEM and IDS/IPS for dynamic malware detection.
- Stay current with new threat actors, malware and analyzing techniques
- Tools used daily are SourceFire IDS/IPS, Kibanna SIEM, Solera PCAP, SiLK netflow and Wireshark
|
| Confidential Research Analyst |
- Use Solarwinds SIEM to review, research and decision all anomalous network traffic. Also tune SIEM as needed and create rules for monitoring purposes
- Respond and triage alerts generated by SourceFire IDS/IPS
- Monitor privileged account usage and make appropriate decisions
- Monitor Lancope Stealthwatch and Solarwinds Orion to monitor and analyze network traffic
- Monitor and mitigate email gateway by identifying and removing malicious email Postini and Symantec Brightmail
- Part of the Incident response and triage team for cyber incidents
- Administer and monitor Symantec Anti-virus and monitor and triage suspect traffic from infected workstations and servers
- Audit and implement DLP policies email using Symantec DLP
- Audit and implement DLP policies at rest using MBAM
- Stay current with industry specific threats and technologies. Present such information to SOC teams to help better adherence to SOX and PCI DSS
- Respond to alerts from FS-ISAC and Dell SOC, Sourcefire IDS/IPS and mitigate vulnerabilities accordingly
- Coordinate with telecom teams and workstation support to ensure completeness of incident remediation
|
| Confidential Security Analyst |
- Maintained HIPS, Firewalls and Anti-Virus of individual machines. Products worked with was Norton 360, Norton anti-virus, Kaspersky and Microsoft Security Essentials to ensure defense diversity
- Provide everyday monitoring of security incidents. Responsible for all software installations and patch management over multiple locations. In charge for all new hardware requisitioning to meet compatibility and security requirements
- Designed and implemented both customer facing and internal wireless network using Linksys hardware. I was also in charge of the security aspects of the wireless networks by implementing proper secure communications
- Train and educate associates of security vulnerabilities associated with unsafe downloads, browsing and social media
|
| TECHNICAL SKILLS | - Experience of auditing DLP solutions in an enterprise level to meet compliance Symantec DLP
- Excellent understanding of IT related security concepts. Enterprise and SOHO
- Experience with SolarWinds SIEM and Solarwinds Orion, Symantec DLP and Symantec End point protection and Lancope Stealthwatch.
- Experience working with SourceFire IDS/IPS
- Excellent troubleshooting ability via phone, email and chat
- Act as team lead, and manage and train multiple employees
- Ability to develop policy guidelines from scratch to be used at an enterprise level
- Experience using SiLK net flow monitoring, Sourcefire IPS and Kibanna LEM.
- Exceptional reporting skills based on scanned results, to be provided to upper management in a non technical fashion if necessary
- Familiarity with network traffic monitoring tools such as Websense
- Help Desk experience. Experience using Remedy and Footprints ticketing systems
|
| LANGUAGE SKILLS | - English Expert
- Bengali Expert
- Spanish, Swedish Beginner
|