Працював в 3 компаніях 3 роки 4 місяці
IT
SOC Analyst
Accord Group
IT
1 рік 6 місяців
07.2024 - до теперішнього часу
I work withSIEM systems, including Elastic and QRadar.I effectively useSOAR solutions.I process incidents, conduct their detailed analysis and create cover letters for clients with attachments for greater detail.I participate in internal meetings and meetings with clients.I develop incident handling playbooks.I constantly work with information security tools such as AlienVault, VT, Spur, 2ip, IPINFO and others.
- Monitoring and analysis of the organization's cybersecurity
- Responding to security incidents identified during monitoring
SOC Engineer L1
Octava Defence
IT
1 рік 2 місяці
06.2023 - 07.2024
Work with SIEM/SOAR systems: Gained experience in working with and maintaining SIEM systems, including Elastic and QRadar. Also usedSOAR solutions to automate processes.Incident Handling: Performed a full cycle of incident handling, including detailed analysis and creation of information letters for clients with attachments for greater detail.Communication: Participated in internal meetings and meetings with customers.Documentation Creation: Developed playbooks (incident handling playbooks) to standardize incident handling processes.IS tools: Constantly worked with information security tools such as AlienVault, VT, Spur, 2ip, IPINFO and others
Security Operator
PIN-UP.TECH
IT
9 місяців
07.2021 - 03.2022
- Distribution and prioritization of tasks / incidents / problems in the JIRA system;
- Processing of applications for end users (resetting passwords, providing access,consulting);
- Registration of applications for end users;
- Communication with commands L2 and L3;
- Monitoring of IS events and incidents in SIEM or IRP system;
- Monitoring the availability of the necessary information on IS events and incidents and reporting L2 on identified problems;
- Testing and monitoring the availability of event sources;
Ключова інформація
- Knowledge of the principles of construction and operation of networks and TCP/IP stack protocols, ISO/OSI models.
- Knowledge of Web Application Security, OWASP Top 10 vulnerabilities.
- Understanding of access control implementation systems (IDM), attack detection subsystems (IDS, IPS).
- Knowledge of the principles of protocol operation: HTTPS,SNMP,SMTP,Kerberos,LDAP,DNS,SSH.
- Basic skills of deploying virtual machines and working with SIEM-systems(work experience with QRadar).
- An average level of command of the English language for working with documentation.
- Responsibility, punctuality, ability to work in a team.
Навчався в 1 закладі
State University of Telecommunication
Information and Сyber Security
Киев, 2023
Володіє мовами
Англійська
середній
Може проходити співбесіду на цій мові
Може проходити співбесіду на цій мові
Російська
вільно
Українська
рідна
Курси, тренінги, сертифікати
Cisco Network Academy "CCNA Security"
- Explain the operation of local area networks and configure devices to connect to LANs and the Internet.
- Configure devices to connect to the Internet and Cloud services.
- Explain how to configure, repair, upgrade, maintain, and troubleshoot laptops and mobile devices.
- Explain how to configure, secure and troubleshoot mobile, OS X, and Linux operating systems.
- Install and share a printer to meet requirements.
- Implement basic host, data, and network security.
Cisco Networking Academy "CCNAv7: Introduction to Networks "
- Configure switches and end devices to provide access to local and remote network resources.
- Explain how physical and data link layer protocols support the operation of Ethernet in a switched network.
- Configure routers to enable end-to-end connectivity between remote devices.
- Create IPv4 and IPv6 addressing. schemes and verify network connectivity between devices.
- Explain how the upper layers of the OSI model support network applications.
- Configure a small network with security best practices.
- Troubleshoot connectivity in a small network.
Cisco Networking Academy "IT Essential"
Explain the operation of local area networks and configure devices to connect to LANs and the Internet.
- Configure devices to connect to the Internet and Cloud services.
- Explain how to configure, repair, upgrade, maintain, and troubleshoot laptops and mobile devices.
- Explain how to configure, secure and troubleshoot mobile, OS X, and Linux operating systems.
- Install and share a printer to meet requirements.
- Implement basic host, data, and network security.
Додаткова інформація
Professional skills
- Ability to work with Jira/Confluence,GitLab.
- Basic deployment of system knowledge like a QRADAR.
- Working with virtual machines (Linux, Unix deployment).
- Basic knowledge of the Linux terminal.
- Knowing the biggest vulnerabilities is the way to deal with them.
- I easily join a team, and quickly catch up on missed material
Andrii
Andrii
SOC Analyst

Київ
повна зайнятість, неповна зайнятість, проектна робота
Характер роботи: віддалена робота, позмінна робота, гібридна, в офісі/на місці
Оновлено 1 місяць тому