i
ivanbg_21

Ivan Bola

@ivanbg_21

Cybersecurity Analyst SIEM EDR

Espagne
Anglais, Espagnol
Certaines informations sont présentées en anglais.
À propos de moi
Certified Cybersecurity Analyst and Detection Engineer specializing in designing, building workflows, and fine-tuning advanced use cases across Splunk, FortiSIEM, Wazuh, and CrowdStrike. My core expertise includes: Detection Engineering: Creating and optimizing custom detection rules to minimize false positives and enhance threat visibility. Alert Analysis & Incident Triage: Investigating complex security alerts and mapping behavior directly to the MITRE ATT&CK framework to track adversary tactics and techniques. SOC Operations: Strengthening security postures through rigorous monitoring... Plus d’infos

Compétences

i
ivanbg_21
Ivan Bola
hors ligne • 
Temps de réponse moyen de 1 heure

Voir mes services

Assistance technique
I will create custom detection rules and use cases in splunk, fortisiem or crowdstrike
Assistance technique
I will do siem tuning and reduce false positive alert noise

Expérience professionnelle

Private

Cybersecurity Analyst

Private • Temps plein

Oct 2022 - Present3 yrs 11 mos

Cybersecurity Analyst & Detection Engineer with over 4 years of hands-on experience spanning advanced Security Operations Center (SOC) environments, incident response, and critical network infrastructure management. - Advanced Detection Engineering & Threat Intelligence: Specializing in designing, creating, and optimizing custom detection logic and rulesets across leading SIEM platforms such as Splunk (SPL), Wazuh, and FortiSIEM. Focused on reducing false positive noise, integrating real-time Indicators of Compromise (IoCs), and mapping threat vectors directly to the MITRE ATT&CK® framework to anticipate sophisticated cyber attacks. - Endpoint Incident Response & Forensics: Conducting deep technical investigations of endpoint security alerts using CrowdStrike, Splunk, and FortiSIEM. Performing meticulous process tree analysis, host containment, and root-breakdown forensics to identify intrusion origins and continuously harden clients' security postures. - Playbooks & Operational Documentation: Defining standardized response strategies and structured playbooks that ensure homogeneous, high-quality execution by operators during active security incidents. - Comprehensive SOC Operations: Extensive background as a SOC Operator managing the complete incident lifecycle under strict Service Level Agreements (SLAs). Proven expertise in continuous service monitoring, alert triage, ticketing governance, and executing escalation workflows while maintaining clear, strategic technical communication with global clients. - Network Infrastructure & Field Support: Practical networking expertise demonstrated during large-scale events like the Mobile World Congress (MWC 2025). Skilled in configuring Cisco Catalyst LAN switches, enterprise wireless networks (WLC 9800/8540 controllers, SSIDs, WLANs), real-time traffic analysis via PRTG, and delivering robust IT provisioning under high-pressure environments.