Post Job Free
Sign in

Cyber Security Analyst Cloud, SIEM & IAM Expert

Location:
New York City, NY
Salary:
70000
Posted:
March 26, 2026

Contact this candidate

Resume:

Md Saiful Islam

Location: PA, USA Mobile: 302-***-**** Email: *****************@*****.*** Visa Status: Green Card Holder SUMMARY

Cyber Security Analyst with 3+ years of experience supporting financial services and consulting environments in SIEM monitoring, cloud security, incident response, and vulnerability management. Experienced with AWS security, Azure security, Identity and Access Management (IAM), and threat detection, aligned with NIST Cybersecurity Framework, ISO 27001, SOC 2, and SOX controls. Skilled in security alert investigation, vulnerability remediation, and security posture reporting across regulated enterprise platforms.

PROFESSIONAL EXPERIENCE

Cyber Security Analyst BNY Mellon USA Oct 2025 – Present

Analyzed enterprise security alerts using Splunk SIEM, AWS CloudTrail, and Microsoft Defender for Endpoint, reviewing 1,800+ monthly security events and accelerating incident investigation turnaround from 4 hours to 95 minutes.

Strengthened cloud protection controls using AWS IAM, AWS GuardDuty, AWS Security Hub, and Azure Security Center, resolving 240 high-risk cloud configuration issues affecting 12 production banking applications.

Detected advanced threats through Endpoint Detection and Response (EDR) telemetry, MITRE ATT&CK framework, and Python log analysis, uncovering 37 privilege escalation attempts targeting treasury platform infrastructure.

Secured regulated reporting environments using Role-Based Access Control (RBAC), network segmentation, and Tenable Nessus vulnerability scanning, resolving 118 critical security findings before 3 financial compliance audit cycles.

Automated incident handling workflows using SOAR playbooks and PowerShell scripting, improving phishing response operations across 9 enterprise business units and eliminating 320 manual investigation hours annually.

Coordinated security posture reviews with cloud and application teams using risk assessment frameworks, presenting security metrics for 6 financial platforms processing 600K+ monthly transactions and guiding remediation planning. Cyber Security Analyst KPMG Bangladesh Oct 2022 – Aug 2023

Assessed enterprise security posture using IBM QRadar SIEM and Carbon Black EDR, investigating 1,700+ security events per month and reducing incident escalation time from 5 hours to 2 hours across 4 client environments.

Executed application security assessments leveraging Burp Suite Professional and OWASP Top 10 testing methodologies, identifying 132 exploitable vulnerabilities in externally facing financial web applications.

Reviewed access governance controls within SailPoint IdentityIQ and Active Directory, remediating 180 excessive privilege assignments and strengthening Privileged Access Management (PAM) controls prior to external audits.

Validated regulatory compliance against SOC 2 Type II, PCI-DSS, and NIST 800-53, documenting 88 control gaps and supporting remediation plans across 6 regulated enterprise platforms.

Performed vulnerability lifecycle management using Tenable.sc integrated with structured patch tracking workflows, reducing critical exposure windows from 12 days to 4 days across 3 enterprise networks.

Delivered cybersecurity risk briefings to client executives, coordinating remediation roadmaps with infrastructure and governance teams and supporting 5 enterprise-wide security transformation initiatives within KPMG’s Risk Advisory practice. Cyber Security Analyst Adani Bangladesh Jul 2020 – Sep 2022

Monitored enterprise and operational technology environments using LogRhythm SIEM and Darktrace Network Detection, analyzing 2,400+ daily security events and reducing incident response time from 6 hours to 2.5 hours across 5 energy facilities.

Secured network infrastructure through Palo Alto Firewalls, Intrusion Prevention Systems (IPS), and VPN configuration management, remediating 160 misconfigured access rules impacting critical operational assets.

Conducted endpoint protection management using Trend Micro Apex One and centralized patch validation through WSUS, closing 420 high-risk vulnerabilities across 1,200+ corporate and industrial endpoints.

Enforced identity governance controls via CyberArk Privileged Access Management and structured access reviews, removing 230 excessive privileged accounts across finance and operational control systems.

Executed incident response investigations aligned with ISO 27001 controls and internal security policies, documenting 75 security cases and supporting regulatory audit submissions across 3 annual compliance cycles.

Coordinated cross-functional security initiatives with infrastructure, SCADA operations, and compliance teams, presenting quarterly risk assessments to senior plant leadership and guiding remediation strategy for 4 mission-critical industrial platforms. TECHNICAL SKILLS

Security Operations: SIEM (Splunk, QRadar, Microsoft Sentinel), log analysis, event correlation, incident detection

Threat & Vulnerability Management: Nessus, Qualys, CVE analysis, vulnerability remediation

Network Security: TCP/IP, firewalls, IDS/IPS, VPNs, DNS security, Wireshark packet analysis

Cloud Security: AWS (IAM, Security Groups, CloudTrail), Azure AD, Microsoft Defender

Identity & Access Management: RBAC, MFA, SSO, Active Directory

Security Frameworks: NIST Cybersecurity Framework, ISO 27001, CIS Controls, OWASP Top 10

Endpoint Security: EDR (CrowdStrike, SentinelOne)

Security Automation: Python, Bash, PowerShell

EDUCATION

Rowan University, Glassboro, NJ, USA M.S. in Cyber Security GPA: 3.5/4.0 Aug 2023 – May 2025 PROJECTS

TryHackMe – Cybersecurity Labs

Completed 17 practical cybersecurity labs on TryHackMe, performing network security analysis, web application testing, privilege escalation, and defensive security monitoring across Windows and Linux environments.

Utilized Nmap, Burp Suite, Metasploit, and Wireshark to conduct vulnerability scanning, packet analysis, web exploitation testing, and post-exploitation enumeration in simulated enterprise attack scenarios. National Cyber League (NCL) – Spring 2024 Competitor

Competed in Individual and Team Games within the National Cyber League (NCL), solving time-bound challenges against nationwide collegiate cybersecurity participants.

Solved practical scenarios in cryptography, network traffic analysis, OSINT, web application security, and log forensics, applying structured incident analysis and investigative techniques. CERTIFICATIONS

CompTIA Security+ ce Link

CompTIA Network+ ce Link

RESEARCH & DEVELOPMENT WORK

Sign Language Recognition for Bangla Alphabets Using Deep Learning Methods – Published in IEEE (IEEE Xplore Digital Library) Link



Contact this candidate