
Arslan A
SOC Analyst and SIEM Engineer
Skills

Bekijk mijn diensten

Portfolio
Werkervaring
SOC Analyst and SIEM Engineer
Security First IT • Fulltime
Mar 2025 - Present • 1 yr 5 mos
💼 Experience & Professional Background SOC Analyst & SIEM Engineer Apprentice | CS Zone Pvt LTD Engineered and maintained 24/7 SIEM monitoring infrastructure (Wazuh & Splunk) across Linux and Windows telemetry sources. Reduced false positives by tuning custom alert thresholds and refining event correlation rules. Investigated and triaged real-time threats including brute-force attempts, unauthorized access, and phishing indicators. Cybersecurity Specialist & Digital Forensics Researcher Built end-to-end automated containment workflows integrating SIEM, webhooks, threat intelligence APIs, and incident case management tools. Conducted vulnerability assessments using industry-standard tools (Nessus, OpenVAS) and delivered actionable remediation reports. 🏆 Key Project Achievements Security Automation Pipeline (SIEM + SOAR + IRIS): Engineered a fully automated threat response pipeline integrating Wazuh SIEM, Shuffle SOAR, VirusTotal API, and DFIR-IRIS case management to automatically analyze and contain suspicious threats in real time. Infrastructure Monitoring Proposal: Authored and presented an executive technical recommendation report to scale network monitoring capabilities up to 200 distinct nodes. Blockchain File Integrity Verification: Researched and implemented a secure file integrity verification framework utilizing blockchain architecture for academic digital forensics research. 🛠️ Core Services I Offer SIEM Platform Deployment & Optimization: Complete setup, log parsing, and custom detection rule configuration (Wazuh, Splunk, Microsoft Sentinel). SOAR & Incident Response Automation: Connecting threat intelligence feeds (VirusTotal, AlienVault) via Shuffle SOAR to streamline threat containment. Endpoint & Network Log Analysis: Analyzing Windows Event IDs, Linux syslogs, PCAP files, and network traffic (Wireshark). Vulnerability Assessments & Hardening: Scanning endpoints, auditing system security policies, and providing step-by-step mitigation g