Faisal Khan

SOC Analyst L2

Role
Security Operations Center Analyst L2 at Innodata Inc.
Location
Ghaziabad, UP, IN
LinkedIn followers
500 followers

About Faisal Khan

I am a Security Operations (SOC) Specialist and part of the first team to establish and operate the SOC at Innodata. From the ground up, I have contributed to setting up monitoring processes, alert workflows, documentation standards, and threat detection capabilities — helping build the organization’s security operations foundation.I have hands-on experience with SIEM operations, threat detection, and endpoint security using ManageEngine Log360, IBM QRadar, Cortex XDR, and Check Point Firewall. Alongside SOC monitoring, I am also involved in the deployment and configuration of IBM QRadar, including preparing the environment, coordinating admin access, onboarding systems, and validating log ingestion and correlation rules.My responsibilities include triaging alerts, analyzing incidents, fine-tuning false positives, and preparing detailed SOC incident reports for management and end-users. I also create daily Check Point firewall security reports covering IPS/IDS activity, scanning behavior, exploitation attempts, and IOC hits.I’ve developed advanced detection use-cases for Active Directory and Domain Controller attacks — Kerberoasting, Pass-the-Hash, Golden Ticket, DC Shadow, brute force, and more. I validated these use cases in a dedicated lab environment consisting of AD, Kali Linux, and ADAudit systems. Additionally, I work with SQL Server audit logs, endpoint threats, and IOC-based investigations across multiple platforms.Building the SOC from scratch has strengthened my skills in collaboration, documentation, process creation, and working closely with IT and NOC teams to enhance detection maturity and improve security posture.I am continually expanding my knowledge in cloud and enterprise security and plan to pursue Azure certifications (AZ-900, AZ-500) to further grow as a cybersecurity professional.

Experience

  1. Security Operations Center Analyst L2

    Innodata Inc.

    Apr 2025 — Present · Noida, IN

    Founding member of the first SOC team at Innodata; contributed to building SOC processes, SOPs, and monitoring workflows.Perform L2-level incident investigation and threat analysis using IBM QRadar, Log360, and Cortex XDR.Active involvement in QRadar deployment, including Console/App Host setup, admin access provisioning, log onboarding, and correlation validation.Generate daily Check Point Firewall security reports (IPS/IDS alerts, scans, exploitation attempts, IOC hits).Conduct phishing email investigations (header checks, URL/attachment analysis, user impact).Develop detection use-cases for AD/DC attacks – Kerberoasting, Golden Ticket, Pass-the-Hash, DC Shadow, NTLM relay, brute-force.Maintain a test lab (AD + Kali Linux + ADAudit) for attack simulation and detection validation.Support SQL Server audit logging and DDL/DML/security log analysis for SIEM visibility.Work with IT/NOC teams for alert tuning, IPS fine-tuning, rule optimization, and onboarding new systems.Create SOC documentation, incident reports, response workflows, and escalation procedures

Education

  • Kendriya Vidyalaya

    12th

  • KRISHNA ENGINERING COLLEGE, GHAZIABAD

    Bachelor of Technology - BTech

Find verified contacts for anyone on LinkedIn

Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.

Free plan included · No credit card required

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.

Faisal Khan — Security Operations Center Analyst L2 at Innodata Inc. in Ghaziabad, UP, IN | Unifers