Sep 2024 – Present
SOC Analyst
Aetna Inc. (CVS Health)Hartford, CT
24/7 security operations for a global healthcare insurer — monitoring, triaging, and investigating alerts across cloud, endpoint, identity, and network telemetry protecting member and claims data.
Show responsibilities ↓Hide responsibilities ↑
- Monitor daily security alerts in Splunk SIEM and Microsoft Sentinel across Azure, on-prem Windows servers, and healthcare applications processing member and claims data.
- Validate triggered alerts with KQL in Azure Log Analytics — unusual authentication behavior, failed MFA attempts, and suspicious access to PHI-related systems.
- Investigate identity risks in Azure AD Identity Protection: risky sign-ins, impossible travel, and conditional access violations.
- Analyze endpoint detections in Microsoft Defender for Endpoint and CrowdStrike Falcon — process activity, registry changes, and file hashes.
- Correlate firewall, DNS, and HTTP logs with endpoint alerts; validate suspicious outbound connections with Wireshark/TCPDump.
- Run IOC checks via VirusTotal and AlienVault OTX and map confirmed behaviors to MITRE ATT&CK.
- Execute SOC playbooks: account disablement, forced password resets, endpoint isolation, and Tier 2 escalation.
- Support HIPAA / NIST CSF-aligned monitoring and security review of new Azure workloads for the CVS Health digital integration initiative.
82%+ SLA compliance maintained for medium/high-severity alerts
~11% reduction in repeat identity-related incidents within one year
- Splunk
- Microsoft Sentinel
- KQL
- Azure AD
- Defender for Endpoint
- CrowdStrike
- Tenable.io
- Nessus
- Wireshark
- ServiceNow
- MITRE ATT&CK
