Cybersecurity Analyst (Contract) — Amdari Inc. (UK)
Worked with SIEM-based log and network traffic analysis to detect, triage, and validate security events that function like labeled security instances for SOC workflows. Reduced false positives by tuning detections and refining alert quality, improving operational decision reliability for downstream incident handling. Used sandbox results and threat-intel signals to corroborate whether observed activity corresponded to phishing, malware, or ransomware behaviors for labeling/verification purposes. • Analyzed logs and traffic using Wireshark and TCPDump to identify and confirm security-relevant patterns. • Tuned detections to reduce false positives and improve incident response times by 40%. • Validated suspicious events using Any.Run/Cuckoo sandbox outcomes plus MITRE ATT&CK and VirusTotal feeds. • Performed SOC real-time detection and response actions to ensure accurate event interpretation.