
Ivan Bola
Cybersecurity Analyst SIEM EDR
Competenze

Consulta i miei servizi


Esperienza lavorativa
Cybersecurity Analyst
Private • Full time
Oct 2022 - Present • 3 yrs 11 mos
Cybersecurity Analyst & Detection Engineer with over 4 years of hands-on experience spanning advanced Security Operations Center (SOC) environments, incident response, and critical network infrastructure management. - Advanced Detection Engineering & Threat Intelligence: Specializing in designing, creating, and optimizing custom detection logic and rulesets across leading SIEM platforms such as Splunk (SPL), Wazuh, and FortiSIEM. Focused on reducing false positive noise, integrating real-time Indicators of Compromise (IoCs), and mapping threat vectors directly to the MITRE ATT&CK® framework to anticipate sophisticated cyber attacks. - Endpoint Incident Response & Forensics: Conducting deep technical investigations of endpoint security alerts using CrowdStrike, Splunk, and FortiSIEM. Performing meticulous process tree analysis, host containment, and root-breakdown forensics to identify intrusion origins and continuously harden clients' security postures. - Playbooks & Operational Documentation: Defining standardized response strategies and structured playbooks that ensure homogeneous, high-quality execution by operators during active security incidents. - Comprehensive SOC Operations: Extensive background as a SOC Operator managing the complete incident lifecycle under strict Service Level Agreements (SLAs). Proven expertise in continuous service monitoring, alert triage, ticketing governance, and executing escalation workflows while maintaining clear, strategic technical communication with global clients. - Network Infrastructure & Field Support: Practical networking expertise demonstrated during large-scale events like the Mobile World Congress (MWC 2025). Skilled in configuring Cisco Catalyst LAN switches, enterprise wireless networks (WLC 9800/8540 controllers, SSIDs, WLANs), real-time traffic analysis via PRTG, and delivering robust IT provisioning under high-pressure environments.