Senior It Engineer (shift Lead) Resume
0/5 (Submit Your Rating)
SUMMARY:
- EnCase is a tool that aids in forensic investigation and helps in gathering evidence which can be submitted in the court of law. As primary SPOC, I am performing the following duties:
- Creating Baseline of critical servers and comparing them against standard baseline
- Analyzing running processes on sensitive assets
- Investigating incidents using keyword search, filters and conditions on a case - by-case requirement
- Creating reports which portrays the chain of custody and the evidences gathered pertaining to specific cases
- Preparing documents that clearly explains the path of investigation in each case
- Creating reports to showcase team’s efforts and progress to the management.
- Forensic investigation of incidents
- Managing the team in the role of Shift Lead
- Creating Monthly and Annual reports that portrays the threat level in the organization and the problems that were tackled by the team
- Analyzing network traffic for suspicious activities and behavior anomalies
- Investigating identified suspicious incidents and providing mitigation steps to reduce the impact
- Creating Incident Handling and forensic procedures/policies
- Senior IT Engineer in IT Security Vertical serving in SIRT (Security Incident Response Team).
- Shift lead to help the team to perform efficiently
- Analyzing network traffic to identify suspicious events and correlate events in real time for both internal and external breaches.
- Advocate mitigation plans and restrict any further intrusion within the specified SLA.
- Conducting forensic investigation of critical incidents to find the root cause of incidents and to suggest steps to prevent similar incidents in future.
- Proactive monitoring to suggest preventive steps for recently identified vulnerabilities thus preventing attacks.
PROFESSIONAL EXPERIENCE:
Confidential
Senior IT Engineer (Shift Lead)
Responsibilities:
- 24/7 support for handling security incident
- Analysis of logs from security devices like
- MacAfee IPS, Firewalls (Cisco ASA and PIX), Symantec Endpoint Protection, Websense DLP, Websense Proxy and RSA enVision (SIEM), NetWitness.