i
ivanbg_21

Ivan Bola

@ivanbg_21

Cybersecurity Analyst SIEM EDR

Espanha
Inglês, Espanhol
Algumas informações são exibidas no idioma inglês.
Sobre mim
Certified Cybersecurity Analyst and Detection Engineer specializing in designing, building workflows, and fine-tuning advanced use cases across Splunk, FortiSIEM, Wazuh, and CrowdStrike. My core expertise includes: Detection Engineering: Creating and optimizing custom detection rules to minimize false positives and enhance threat visibility. Alert Analysis & Incident Triage: Investigating complex security alerts and mapping behavior directly to the MITRE ATT&CK framework to track adversary tactics and techniques. SOC Operations: Strengthening security postures through rigorous monitoring... Saiba mais

Habilidades

i
ivanbg_21
Ivan Bola
offline • 
Tempo médio de resposta: 1 hora

Conheça meus serviços

Suporte Técnico
I will create custom detection rules and use cases in splunk, fortisiem or crowdstrike
Suporte Técnico
I will do siem tuning and reduce false positive alert noise

Experiência profissional

Private

Cybersecurity Analyst

Private • Período integral

Oct 2022 - Present3 yrs 11 mos

Cybersecurity Analyst & Detection Engineer with over 4 years of hands-on experience spanning advanced Security Operations Center (SOC) environments, incident response, and critical network infrastructure management. - Advanced Detection Engineering & Threat Intelligence: Specializing in designing, creating, and optimizing custom detection logic and rulesets across leading SIEM platforms such as Splunk (SPL), Wazuh, and FortiSIEM. Focused on reducing false positive noise, integrating real-time Indicators of Compromise (IoCs), and mapping threat vectors directly to the MITRE ATT&CK® framework to anticipate sophisticated cyber attacks. - Endpoint Incident Response & Forensics: Conducting deep technical investigations of endpoint security alerts using CrowdStrike, Splunk, and FortiSIEM. Performing meticulous process tree analysis, host containment, and root-breakdown forensics to identify intrusion origins and continuously harden clients' security postures. - Playbooks & Operational Documentation: Defining standardized response strategies and structured playbooks that ensure homogeneous, high-quality execution by operators during active security incidents. - Comprehensive SOC Operations: Extensive background as a SOC Operator managing the complete incident lifecycle under strict Service Level Agreements (SLAs). Proven expertise in continuous service monitoring, alert triage, ticketing governance, and executing escalation workflows while maintaining clear, strategic technical communication with global clients. - Network Infrastructure & Field Support: Practical networking expertise demonstrated during large-scale events like the Mobile World Congress (MWC 2025). Skilled in configuring Cisco Catalyst LAN switches, enterprise wireless networks (WLC 9800/8540 controllers, SSIDs, WLANs), real-time traffic analysis via PRTG, and delivering robust IT provisioning under high-pressure environments.