Post Job Free
Sign in

Cyber Security Analyst with Incident Response Expertise

Location:
Raleigh, NC
Posted:
June 05, 2026

Contact this candidate

Resume:

Liva Zarina Ates

US Citizen

336-***-**** ********@*****.***

Professional Summary:

• A highly proficient CompTIA Security+ certified Cyber Security Analyst with 5+ years of professional experience in the education field and 3+ years of professional experience in the security field.

• Specialized in security analysis and incident response.

• Experienced in hands-on projects in monitoring and analysis of potential and active threats using security tools and processes.

• Withholding leadership qualities with emphasis on individual and team effort backed with excellent analytical, problem solving, coordination, and communication skills.

• Excellent interpersonal skills, a cross functional team player with a problem-solving mindset who works well under a high stress environment.

• Expert knowledge in understanding the security aspect, requirement specifications and documentations.

• Works closely with team members to understand requirements and progressively strengthen cyber security defense measures.

• Experienced in working in a team environment with the strong ability to collaborate with a team as well as individually.

Technical Skills & Tools:

• Security: Splunk SOAR, Splunk Cloud, Proofpoint TAP, Akamai, Anomali ThreatSteam, Crowdstrike Falcon, Crowdstrike University, Expel, Proofpoint SmartSearch, Proofpoint TRAP, Qualys, VirusTotal, Malware Analytics/Threat Analutics, Wiz, Sharepoint, Nessus, Nmap, Axonius, Linux Command Line Tools, Domain Tools, Phishing Analysis, Jira, IDS/IPS

• Networking: Wireshark packet analysis, DNS, TCP/IP

• Programming Language: HTML, CSS

Languages:

• Russian (Native or Bilingual Proficiency)

• Turkish (Native or Bilingual Proficiency)

• Farsi (Native or Bilingual Proficiency)

• English (Native or Bilingual Proficiency)

Professional Experience:

United Airlines Chicago/IL Nov/2022- Present

Incident Response and Security Analyst

• Work on analyzing our Incident Response team’s queue full with alert tickets generated for my and my teammates critique.

• Ticket severity varies from Critical, High, Medium, Low with Critical being the highest priority to be worked on and Low being the lowest priority to work on, I work on tickets that are identified as Critical alerts, High alerts, Medium alerts, and Low alerts and complete my analysis on the tickets.

• By using various different tools on the alert ticket, I thoroughly analyze the ticket and use my critical thinking to decide on whether the alert with the details provided as well as identified by me is malicious and should be looked into further or if they are to be expected due to the details provided.

• Experienced in many different tools that are used daily if not hourly to identify and closely look into for a decision on the ticket, such as Splunk SOAR, Proofpoint TAP, Crowdstrike, Malware Analytics etc.

• Trained and continue training new joiners on the tools being used and day to day responsibilities on our team by providing a full knowledge transfer.

• Bi-weekly work on generating a well put presentation of both nationwide and international malware attacks, research to have all the details ready to be presented in our bi weekly call to the whole team and answer questions.

• Perform Incident handling on the incidents identified and are meant to have a resolution quickly by working on analyzing and thoroughly looking into the issue identified and come up with a plan to handle the incident.

• Continuously participate in training on a subject picked for the week with my group of teammates, later on being expected to have key takeaways from the training.

• Generate a report to my manager of the alerts, incidents and important analysis done from my end and communicate all the matters through.

• Continuously attend daily, weekly, monthly team meetings with our team to discuss important matters and updates both individually and as a team.

• Participate in team gatherings that occur throughout the year for our teams to catch up.

• Recognized by peers and managers and upper management on the hard work put in during calls both individually and in team setting.

• Experienced in being assigned on a day shift on call every 5 weeks to be the point of contact on the alerts that come in as critical and being the subject matter expert on anything cybersecurity team can contact on such as the incidents or other important matters with the duration being a week.

• Experienced in being assigned on a night shift on call every 5 weeks to be the point of contact cybersecurity team can contact me, such as the incidents or other important matters with the duration being a week.

• Both day and night shifts require attention to detail and being the key point of contact during the day and night and once done with the shift, being expected to summarize the activity. CyberNow Labs Fairfax/VA

Security Operations Center Analyst Jan/2020- Oct/2022

• Monitor and analyze SIEM alerts through Splunk and IBM QRadar.

• Identify security anomalies for investigation and remediation.

• Conduct analysis to determine the legitimacy of domains, files and emails by using online resources such as AnyRun, VirusTotal, and MX Toolbox.

• Experienced with fundamentals of information security including network technologies and tools, identity and access management.

• Experienced with network security, implementing secure systems and risk management.

• Performed analysis on PCAP files, narrow down the anomaly traffic with Wireshark, examined the details of the infected hosts and wrote IOC on executive summary reports.

• Conducted log analysis on Splunk and IBM QRadar SIEM solutions and provided recommendation to the technical teams via JIRA ticketing system.

• Continuously studying common cyber-attach types and create examples of them by using tools such as Kali Linux and SEtoolkit.

• Examine existing policies, procedures in order to verify compliance with National Institutes of Technology (NIST) Risk Framework.

• Identified and continuously working to identify opportunities for improvement to enhance team-wide capabilities.

• Experienced in tools such as NMap, Kali Linux, and Nessus to continuously strengthen cyber security infrastructure.

• Continuously learning new technologies to improve on in order to add value to my team and company.

• Recognized in the staff meetings for top performance both as an individual as well as within the team.

Bright Horizons Tysons/VA

Instructor of Early Child Education March/2018 –Dec/2020

• Experienced in working closely with students to develop the areas of knowledge they need.

• Provided a range of instructional, management, and assessment strategies to meet the different needs of students.

• Learned from class instructional coaches to become a mentor to kids.

• Helped students identify new interest and drive their own continued learning betting the curriculum.

• Helped facilitate a safe, supportive, and energetic community that welcomes the various needs and learning styles of students.

• Created and maintained a classroom environment conductive to learning and one that engages the learner experientially.

• Established and communicated clear objectives for all education activities.

• Differentiated instructions for all learners based on their level of knowledge and abilities. Triad Math and Science Academy Greensboro/NC

Instructor of ESL 2013-Feb/2018

• Participated in creating, administrating, revising, and grading assessments.

• Collaborated with colleagues across content areas and grade levels.

• Attend and actively participated in all staff meetings including grade level meetings and sessions.

• Conducted parent-teacher conferences as needed, as well as on- going parent communication.

• Organized teaching groups for individual students based on their skill level.

• Advised students, mediated concepts and taught them how to be mediators to increase student involvement in the curriculum.

• Maintained active communication with Charter School administrators, parents and other faculty and staff members on individual student progress and program enhancements.

• Earned State License of Teaching in order to adhere to North Carolina Teaching Standards as outlined by the North Carolina Department of Education. v Certifications :

CompTIA Security+

Splunk Core Certified User

Vulnerability Management Specialist by Qualys

IBM Cybersecurity Analyst

DDOS Attacks & Defenses by University of Colorado

OWASP Top 10 - 2021

Google Cybersecurity Professional Certificate

AWS Certified Cloud Practitioner

Certified GCP Associate



Contact this candidate