Ramansh Sharma
Ramansh Sharma
Work History

Sr. Security Analyst L2

AMD · Hyderabad

Oct 2023 – Present·2 yrs 9 mos

• Advanced Threat Detection and Response: Leveraged Splunk and XSOAR for comprehensive log analysis, focusing on compromised accounts, phishing attacks, and malicious scripts. Implemented automation for routine security tasks, significantly reducing response times and improving incident management workflows. • Endpoint Security and Vulnerability Management: Used CrowdStrike and Microsoft Defender for advanced endpoint detection and response, effectively mitigating malicious activities, including persistence techniques. Conducted continuous monitoring, vulnerability assessments, and regular patch management to safeguard endpoints from emerging threats. • Incident Management and Process Optimization: Utilized the ServiceNow portal for systematic incident reporting and tracking, enhancing overall incident management efficiency. Created use cases and Standard Operating Procedures (SOPs) on Splunk to optimize log management and analysis processes. • Cybersecurity Training and Proactive Measures: Conducted training sessions for subordinates on phishing analysis and the risks associated with USBs to enhance cybersecurity awareness. Proactively identified anomalies such as unusual network traffic and unauthorized access attempts, addressing security gaps promptly to safeguard AMD and its partners from potential threats.

Security analyst L2

Connectwise · Pune

Feb 2022 – Oct 2023·1 yr 8 mos

• Monitoring of 6 hundred thousand plus endpoints, belonging to multiple partners from multiple locations, SentinelOne incident alerting and reporting using FreshDesk console • Hands on experience in dealing with cases related to live attacks involving Ransomware, Emotet, Mimi Katz, Mshta, PowerShell Executions, Lateral Movements and analyzing security levels of multiple security devices and raising incident for any kind of security breaches, includes CIA frame work. • Investigating an offence that is triggered by event and different threats, PowerShell Scripts, Malware, Web Attacks, Linux commands and Scripts. • Hands on experience of Extended Endpoint Detection and Response tools (SentinelOne & BitDefender) • Incident Response and Forensic Analysis also include the CIA framework. • Security Incident Handling and analyzing events and raw logs for possible Incidents and finding RCA for the same. • Writing analysis reports on the threats like Ransomware, Botnets, Malicious PowerShell scripts, etc. and sending the information via ticket using the ticketing tool Freshdesk • Handled escalations pre- and post-attacks on the server/desktops and take the required remediation steps.

Communities

GDG New Delhi

58354 members