CYBERSECURITY ENGINEER & SOC ANALYST
2024-11 → ACTIVEAmazure Technology Pvt Ltd
- Triage 300+ alerts weekly across endpoint and SIEM in a 24x7 multi-customer environment; cut false positives via refined Falcon detection policies.
- Design and deploy Falcon Fusion SOAR playbooks automating triage, device isolation and analyst notification — directly lowering MTTR.
- Administer and fine-tune CrowdStrike Falcon across 5,000+ endpoints: deployment, policy, troubleshooting.
- Maintain a version-controlled GitHub repository of SIEM detection rules enforced across client tenants.
- Design identity-based conditional access policies; run ITDR coverage.
- Evaluate and onboard new products (WatchGuard, Kitecyber) into SOC workflows.
- Author incident and risk reports; document timelines and root cause for audit.
- Map threat intel and IOCs to MITRE ATT&CK to close coverage gaps.
- Lab/POC evaluation of Falcon MCP Server for agent-assisted triage.
