Associate Cyber Security Analyst
Monitor and correlate log sources in Splunk SIEM through custom SPL queries mapped to MITRE ATT&CK techniques, detecting and escalating security incidents across critical airport infrastructure
Scan the organisation-wide application inventory to identify vulnerable versions, correlating them against published security advisories and classifying them by exploitability and criticality before reporting them to the owning teams for patching
Analyse EDR telemetry in Cisco AMP during alert investigations, applying host isolation and IOC-based blocking