Loading candidate details...

Justin S – Performed 24×7 security monitoring, alert triage, and threat hunting across on-premise, cloud, and hybrid client infrastructures. • Investigated security events and anomalies using SIEM platforms (Wazuh, Elasticsearch, FortiAnalyzer) to identify suspicious activity and potential cyber threats. • Onboarded and analyzed security logs from multiple sources including FortiGate firewall, AWS GuardDuty, Active Directory, endpoint security platforms, and system logs. • Developed and tuned SIEM detection rules and correlation logic, improving detection accuracy and reducing false positives across multiple environments. • Investigated and analyzed FortiGate firewall logs via FortiAnalyzer, identifying policy violations, malicious traffic patterns, and network reconnaissance attempts. • Monitored and investigated AWS GuardDuty security findings, including credential misuse, anomalous API activity, and reconnaissance behavior in cloud environments. • Conducted cloud security monitoring in GCP using Elastic, reviewing security logs and alerts for suspicious activity and configuration risks. • Correlated alerts across SIEM, EDR/XDR, firewall, identity, and cloud platforms to detect multi-stage attacks and lateral movement attempts. • Implemented SOAR workflows using Shuffle to automate alert enrichment, IOC validation, ticket creation, and incident notifications. • Managed Indicators of Compromise (IOCs) including IP addresses, domains, URLs, and file hashes across security platforms to support threat detection and investigation. • Investigated endpoint threats using ESET XDR and Sophos EDR/XDR, performing containment, remediation, and post-incident forensic analysis. • Conducted penetration testing and vulnerability assessments for web applications, servers, and infrastructure, providing remediation recommendations based on risk severity. • Monitored Active Directory security events, including suspicious logons, privilege escalation attempts, and account misuse. • Produced incident investigation reports, threat advisories, and executive summaries for internal teams and client stakeholders. • Collaborated with internal security teams and client engineers during incident response, root cause analysis, and security improvement initiatives. | FindITQ