Faisal Khan
SOC Analyst L2
- Role
- Security Operations Center Analyst L2 at Innodata Inc.
- Location
- Ghaziabad, UP, IN
- LinkedIn followers
- 500 followers
About Faisal Khan
I am a Security Operations (SOC) Specialist and part of the first team to establish and operate the SOC at Innodata. From the ground up, I have contributed to setting up monitoring processes, alert workflows, documentation standards, and threat detection capabilities — helping build the organization’s security operations foundation.I have hands-on experience with SIEM operations, threat detection, and endpoint security using ManageEngine Log360, IBM QRadar, Cortex XDR, and Check Point Firewall. Alongside SOC monitoring, I am also involved in the deployment and configuration of IBM QRadar, including preparing the environment, coordinating admin access, onboarding systems, and validating log ingestion and correlation rules.My responsibilities include triaging alerts, analyzing incidents, fine-tuning false positives, and preparing detailed SOC incident reports for management and end-users. I also create daily Check Point firewall security reports covering IPS/IDS activity, scanning behavior, exploitation attempts, and IOC hits.I’ve developed advanced detection use-cases for Active Directory and Domain Controller attacks — Kerberoasting, Pass-the-Hash, Golden Ticket, DC Shadow, brute force, and more. I validated these use cases in a dedicated lab environment consisting of AD, Kali Linux, and ADAudit systems. Additionally, I work with SQL Server audit logs, endpoint threats, and IOC-based investigations across multiple platforms.Building the SOC from scratch has strengthened my skills in collaboration, documentation, process creation, and working closely with IT and NOC teams to enhance detection maturity and improve security posture.I am continually expanding my knowledge in cloud and enterprise security and plan to pursue Azure certifications (AZ-900, AZ-500) to further grow as a cybersecurity professional.
Experience
Security Operations Center Analyst L2
Apr 2025 — Present · Noida, IN
Founding member of the first SOC team at Innodata; contributed to building SOC processes, SOPs, and monitoring workflows.Perform L2-level incident investigation and threat analysis using IBM QRadar, Log360, and Cortex XDR.Active involvement in QRadar deployment, including Console/App Host setup, admin access provisioning, log onboarding, and correlation validation.Generate daily Check Point Firewall security reports (IPS/IDS alerts, scans, exploitation attempts, IOC hits).Conduct phishing email investigations (header checks, URL/attachment analysis, user impact).Develop detection use-cases for AD/DC attacks – Kerberoasting, Golden Ticket, Pass-the-Hash, DC Shadow, NTLM relay, brute-force.Maintain a test lab (AD + Kali Linux + ADAudit) for attack simulation and detection validation.Support SQL Server audit logging and DDL/DML/security log analysis for SIEM visibility.Work with IT/NOC teams for alert tuning, IPS fine-tuning, rule optimization, and onboarding new systems.Create SOC documentation, incident reports, response workflows, and escalation procedures
Education
Kendriya Vidyalaya
12th
KRISHNA ENGINERING COLLEGE, GHAZIABAD
Bachelor of Technology - BTech
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.