01
Tier 1 SOC Analyst (OJT Internship)
CyTech Development and Operations Inc.
- Monitored live security alert streams across 10+ enterprise clients simultaneously on the Aquila dashboard wallboard, triaging high-volume incoming telemetry and separating benign background noise from active threats.
- Conducted deep log correlation and forensic investigation in Elastic (Kibana/KQL) across historical timeframes (7 to 90+ days), analyzing authentication events, source IPs, ASNs, and user behavior.
- Investigated Microsoft 365 / Azure AD identity alerts (OAuth2 authorization errors, account lockouts, atypical travel logins correlated with MDM device compliance) and Defender Threat Intelligence phishing signals (SPF/DKIM/DMARC spoof analysis).
- Triaged AWS CloudTrail data/management events (S3 unauthenticated bucket access, STS cross-account AssumeRole session verification) and Fortinet FortiGate network security events (SSL-VPN brute force enumeration and web filter blocks).
- Analyzed SentinelOne Behavioral AI endpoint detections (DBT - Executables, ransomware heuristics, process execution trees, SHA256 hashes) and verified automated mitigation status (quarantine, kill, remediate).
- Documented comprehensive incident reports adhering to a strict two-section protocol ('What do we see?' / 'Where do we see it?') in Aquila and managed escalations via the Tier 2 Kanban board.