Saleh Ahmed
Senior Analyst, Information Security (Soc) @CIBC
Signup · Get unlimited contacts
WORK HISTORY
Senior Analyst, Information Security (Soc) @CIBC
Toronto, ON, CA
Monitoring of incoming submitted spam samples from end-users to provide assessment and analysis for malicious threats to our organization and possible campaigns being acted against our organization- Triaging of incoming SIEM system alerts with emphasis on determining the level of risk and if an event needs to be escalated for investigation- Performed in-depth analysis of security alerts and system events, conducting thorough triage and investigations to deliver detailed threat assessment reports- Developing alert response runbooks and security documentation to improve detection and response efficiency- Conducting security log analysis to identify, assess, and respond to suspicious or unauthorized activities in line with organizational security policies- Collaborated with cross-functional teams, including security delivery and threat detection, to strengthen and maintain effective security controls are in place- Providing assistance for any ad-hoc requests from our upper management in regard to assessments or inquiries- Providing first-line responses for day-to-day operational tasks related to the ongoing support of the SOC.
EDUCATION
Ontario Tech University
Master's degree, Information Technology Security
American International University-Bangladesh
Bachelor of Science - BS, Computer Science
ABOUT SALEH AHMED
As a skilled SOC Analyst Level-1, I possess nearly a year of experience in monitoring, investigating, and responding to security incidents, along with four years of expertise in Cybersecurity Project Management. My proficiency in utilizing a diverse range of security tools and technologies enables me to efficiently perform triage, analyze threats, and generate technical reports to facilitate incident response and remediation. With a talent for maintaining the overall security of organizational systems and data, I am committed to delivering effective and proactive cybersecurity solutions.Skills- Experienced in threat intelligence, incident response, monitoring and investigating security events and alerts- Skilled in triaging and performing thorough threat analysis, providing detailed incident reports to improve organizational security and make clear recommendations on mitigation- Proficient in malware analysis, spam/phishing detection, PCAP and log analysis, and vulnerability assessments using various security tools and technologies- In-depth knowledge of security operations procedures, networking protocols, and TCP/IP- Skilled in writing Splunk queries, searching, monitoring, analyzing and visualizing Splunk logs- Skilled in mitigating threats by using Microsoft 365 Defender and Microsoft Sentinel- Familiar with the Python, PowerShell, MITRE ATT & CK, ITIL framework, Governance, Risk, and Compliance- Effective communication of complex technical information to both technical and non-technical stakeholders- Ability to excel in a face paced, challenging, operations environment with 24/7 shifts.Certification:Cisco Certified Cyber-Ops Associate (200-201 CBROPS)SC-200: Microsoft Certified: Security Operations Analyst Associate,Training-CompTIA Security+ SY0-601-Microsoft Security Operations Analyst (SC-200)- Ongoing-CISSP (Certified Information Systems Security Professional)-Splunk Core Certified User (SPLK 1001)
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.