Joseph Cruz
Senior Security Analyst @Blackpoint Cyber
Signup · Get unlimited contacts
WORK HISTORY
Senior Security Analyst @Blackpoint Cyber
Directed team efforts to optimize queue management, ensuring timely and effective incident handling.• Trained and mentored analysts, supporting their growth from junior to senior roles through hands-on guidance.• Collaborated directly with customers to resolve incidents efficiently and address their security concerns.• Analyzed and resolved escalated Tier 1 alerts on MDR platform, ensuring proper remediation and threat containment.• Investigated threat actor activity, including ransomware and nation-state tactics, managing multiple major incidents monthly.• Resolved high-risk email alerts involving suspicious logins, brute-force attacks, and malicious software incidents such as SolarWinds.• Identified and remediated potential outbreaks preventing further escalation and network compromise.• Refined alert suppression and tuning processes to minimize false positives and improve detection accuracy.• Isolated compromised devices to prevent lateral movement and contain malicious activity effectively.• Conducted malware analysis using Capev2 automated sandbox, uncovering malicious behaviors and generating actionable IOCs.• Delivered tuning recommendations based on observed activity to enhance system security and reduce vulnerabilities.• Performed proactive threat hunting using IOCs and IOAs to identify compromised devices and potential security breaches.• Conducted log analysis using customer-provided data to detect and investigate security incidents.• Performed incident response activities, developed detailed IR reports, and provided actionable security recommendations.
ABOUT JOSEPH CRUZ
Senior Security Analyst with over 7 years of experience in cybersecurity operations, incident response (IR), threat hunting, and malware analysis. Proven ability to analyze and mitigate complex security incidents involving ransomware, nation-state actors, and high-risk threats. Skilled in leading and mentoring teams, managing SIEM platforms (Splunk, Qradar, SecureWorks), endpoint security tools (CrowdStrike, Carbon Black), and IDS/IPS solutions (Cisco, Palo Alto). Adept at collaborating with clients to resolve issues and providing actionable security recommendations to strengthen organizational defenses.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.