
Fazal K
Cyber Security Analyst
Compétences

Voir mes services

Expérience professionnelle
Not Found
Temps partiel • 2 yrs 3 mos
Cyber Security Analyst/Security Engineer
Jan 2026 - Present • 6 mos
o Monitor, triage, and investigate security alerts across Microsoft Sentinel, Defender XDR, Purview, Intune, EDR, and SIEM platforms. o Analyse endpoint, identity, cloud, audit, and DLP events to identify suspicious activity, root cause, affected assets, and required remediation. o Investigate incidents in Defender XDR and Sentinel using alert timelines, device evidence, identity logs, audit records, and user activity. o Build and tune Sentinel KQL analytics rules for failed sign-ins, suspicious PowerShell activity, endpoint threats, Defender incidents, and data loss events. o Support endpoint security operations through Defender for Endpoint onboarding, device compliance checks, ASR rules, antivirus policies, and endpoint protection controls. o Review Purview security and compliance alerts covering DLP, sensitivity labels, insider risk, eDiscovery, audit, and communication compliance. o Create incident response workflows and automation playbooks to improve alert handling, SOC visibility, and notification processes. o Perform detection testing and attack simulation to validate alert logic, reduce false positives, and improve response readiness. o Prepare incident reports covering investigation findings, evidence, root cause, business impact, and practical remediation actions. o Support Azure and Microsoft 365 security hardening across identity, access control, monitoring, compliance, and secure configuration. o Perform web application security review and VAPT activities, including vulnerability validation, risk prioritisation, remediation guidance, and reporting.
Cloud Support and Security Engineer
Mar 2023 - Dec 2024 • 1 yr 9 mos
o Designed secure AWS and Azure infrastructure and supported cloud deployments using Terraform, Ansible, Docker, Kubernetes, Bash, and PowerShell. o Developed cloud incident response playbooks and investigated anomalous endpoint, application, network, and cloud log activity. o Embedded DevSecOps controls in delivery workflows through SAST, container scanning, IaC scanning, and DAST practices. o Designed disaster recovery and resilience architectures using Terraform to support business continuity and secure service restoration. o Worked with engineering and DevOps stakeholders to improve security posture without losing operational practicality.