· Expertise in Azure Sentinel, Macafee SIEM, AWS Guarduty, Zscalar Smokescreen, Trend Micro XDR, Archer, Service Now, KQL, NetworkSecurity, IDS/IPS, Firewalls.
· Performing real-time monitoring, investigation, analysis, reporting and escalation of security events from multiple log sources todetermine intrusion and malicious events.
· Working level knowledge on security solutions like Antivirus, firewall, IPS, IDS, Email gateway, proxy, IAM, TI, VA scanners, WAF.
· Strong hand-on experience in security management tools like Microsoft Azure Sentinel, SIEM, AWS Guarduty, Zscalar Smokescreen, Trend Micro XDR, security incident and event management.
· Good experience in working and communication with cross-functional IT infrastructure teams like network, system, database, application,security to build and manage effective security operations.
· Understand and adhere to corporate security policies and help in creation of procedures / SOPs when required. Understanding the basics ofthreat intelligence, detection & response.
· Ensure all service management procedures are being followed and SLAs met.
· Experience in analyze security event data from the network (Azure sentinel).
· Experience in Investigate malicious phishing emails, domains and IPs using Open-Source tools and recommend proper blocking based onanalysis.