- Monitored security alerts across endpoints, cloud, network, and email systems using tools like CrowdStrike, Microsoft Defender, Cybereason, and Trellix.
- Investigated and analyzed threats using process trees, timelines, threat graphs, and attack stories to identify root causes.
- Performed threat hunting and collaborated with SOC teams to improve detection capabilities and reduce false positives.
- Configured and managed EDR/XDR policies, firewall rules, and allow/deny lists to strengthen endpoint and network security.
- Blocked malicious indicators (IPs, URLs, files), contained compromised accounts, and implemented DLP controls to prevent data leakage and unauthorized access.
Skills: Cybersecurity, SOC Operations, Threat Hunting, Incident Analysis