No more typing reviews! Try our Samantha, our new voice AI agent.

Enterprise SOC Monitoring & Incident Response

Koyena Paul - PeerSpot reviewer
Managed Security Services Associate at Accenture
3 people affected
2 people managed
3 month project

Project Description

Designed and implemented a SOC monitoring workflow using Splunk SIEM to detect, investigate, and respond to security incidents across endpoint, email, and network environments. Performed log analysis, IOC investigation, MITRE ATT&CK mapping, and root cause analysis while integrating ServiceNow for incident tracking. Focused on reducing false positives and improving overall threat detection efficiency.

Lessons Learned

If I were to do this project again, I would place greater emphasis on automation and scalability. I would integrate additional security tools and threat intelligence feeds, implement automated response workflows to reduce manual effort, and expand the monitoring scope to include cloud workloads. I would also improve dashboard visualization and optimize detection rules to further reduce false positives and improve overall incident response efficiency.

Highlights

Ahead of schedule
Under budget
Received recognition / award
Support from colleagues

Difficulties

Management had to be convinced

Products Used

Technical Skills Used

  • SIEM Monitoring, Splunk SIEM, Threat Detection, Threat Hunting, Incident Response, Log Analysis, Log Correlation, IOC Investigation, Alert Triage, Root Cause Analysis (RCA), Network Traffic Analysis, HTTP & SMTP Log Analysis, Endpoint Detection & Response (EDR)
  • Kolkata (IN)22.562688.363