Summary
Overview
Work History
Education
Skills
Globalcertifications
Accomplishments
Timeline
Generic
Anmol Singh

Anmol Singh

Greater Noida

Summary

· I have 6+ years of experience in SOC, with a demonstrated history of working with multiple organizations spread across different industries and 100+ countries.

· Investigating and responding to security incidents by Triage incident details, analyzing root causes, and recommending remediation strategies

· Incident response Analyst or Incident coordinator for high priority or major widespread incidents like DDOS, APT attacks ... and was responsible for mitigating the risk, coordinating with stakeholders, Clients, and Preparing the RCA of the incident.

· Mentoring the L1 analysts on monitoring, investigating through the tools available and other operational activities, assigning the tasks.

· Expertise in complete M365 Defender security stack i.e. Azure Sentinel, Microsoft Defender for Endpoint, MDO, MDI, MDCA

· Building and fine-tuning the existing correlation rules for improved alerting of incidents.

· Prepared Incident Response Plan & Standard Operating Procedure.

· Creating Monthly Reports, Dashboards and presenting SOC Metrics to management.

Overview

9
9
years of professional experience

Work History

GSOC Team Lead

KPMG
06.2020 - Current

· Shift lead in the monitoring team and providing L2 support to stakeholders/clients on handling security incidents.

· Performing client engagement and conducting discussions on several threat scenarios, upcoming trends in security.

· Active involvement in threat research around various open- source tools and portals.

· Involved with the content team at client location in investigating and probing False Positives and work with them to whitelist/fine-tune current processes.

· Triaging, reporting for the logs flowing through the event sources and event traffic patterns.

· Mentoring the L1 analysts on monitoring, investigating through the tools available and other operational activities.

· Perform risk assessments on Microsoft Defender for cloud.

GSOC - Senior Analyst

KPMG
11.2019 - 06.2020

· Perform detailed investigation and response to security alerts in Microsoft Security Stack, RSA SA and several High priority security incidents i.e., attacks like DDoS, Data leakage, APT etc.

· Analysis of IOCs and providing end to end investigation on zero-day security incidents.

· Analysis of Spoofed Emails/malicious attachment/malicious URLs.

· Perform threat hunting and creation of detection rules on Sentinel through KQL (Kusto Query Language).

· Create Process and Procedures for Handling High Priority Incidents (Data Leakage, DDoS etc.).

· Troubleshooting in log parsing and log quality checks.

SOC Engineer

Orange Business Services
02.2019 - 11.2019
  • Working as an Information Analyst Specialist in MSSP Environment
  • Handling Multiple Clients for day-to-day SOC Operations
  • Responsible for Administration of SIEM Solutions ArcSight, Q Radar
  • Also responsible for L2 Operations for multiple clients
  • Patch Management for the assets of multiple clients
  • Responsible for Vulnerability Scanning for Asia region (9 countries) including Server and workstation
  • Generating Vulnerability report and customization of reports and uploading
  • Managing health of ArcSight ESM Manager
  • Analyzing client ‘s existing network and security setup for Enhancements and Improvements
  • Responsible for Change raise under SNOW and BMC Remedy by following proper change management process.

Information Security Professional

DXC Technology (Formerly Computer Science Corporation)
01.2016 - 02.2019
  • Working as an Information Analyst Specialist in MSSP Environment
  • Handling Multiple Clients for day-to-day SOC Operations
  • Responsible for Administration of SIEM Solutions ArcSight, Q Radar
  • Also responsible for L2 Operations for multiple clients
  • Patch Management for the assets of multiple clients
  • Responsible for Vulnerability Scanning for Asia region (9 country) including Server and workstation
  • Generating Vulnerability report and customization of reports and uploading
  • Managing health of ArcSight ESM Manager, troubleshooting Issues related to SIEM
  • Also responsible for L2 Operations of McAfee IPS (Network Security Manager)
  • Analyzing client ‘s existing network and security setup for Enhancements and Improvements
  • Responsible for Change raise under SNOW and BMC Remedy by following proper change management process

Education

Master of Science - Information Security

IGNOU
Noida, India

PGDIS -

IGNOU
Noida
12-2023

BSc. IT -

Kalinga University
06-2017

Diploma in Information Technology -

Ambition Institute of Technology
01.2014

10th -

CBSE Board
01.2010

Skills

    Incident Response

    Cloud Security and Content Management (Azure)

    Workbook creation on Microsoft Sentinel

    Threat Hunting

    SIEM (RSA Net witness, Azure Sentinel, Q-Radar, ArcSight)

    Google Suite /Google Admin

    Network Firewalls, proxy technologies, EDR(MDE)

    Email Security: Protection (TAP) & Proofpoint Protection on Demand (POD)

    Ticketing Tool: BMC Remedy Tool, ServiceNow, RSA Archer

    TECHNOLOGIES USED

    MICROSOFT Security Stack (M365D)

    Microsoft Sentinel

    Microsoft Defender for Cloud (MDC)

    Microsoft Identity Protection (MDI)

    Microsoft Defender for Endpoint (MDE)

    Microsoft Defender for Cloud Apps

    Microsoft AD Identity Protection

    Microsoft Defender for Office

Globalcertifications

  • PCDRA
  • Microsoft Certified: Azure Security Engineer Associate
  • CC - Certified in Cybersecurity (Isc2)
  • RED HAT Certified System Administrator v7, 09/19/16, 160-195-244
  • Certified Ethical Hacker, 07/31/17, ECC66937439471
  • EC-Council Certified Security Analyst, 07/11/18, ECC49847165304

Accomplishments

  • Continuously among the top performers in my team at DXC Technology.
  • KPMG GSOC Excellence
  • KPMG Encore Award

Timeline

GSOC Team Lead

KPMG
06.2020 - Current

GSOC - Senior Analyst

KPMG
11.2019 - 06.2020

SOC Engineer

Orange Business Services
02.2019 - 11.2019

Information Security Professional

DXC Technology (Formerly Computer Science Corporation)
01.2016 - 02.2019

Diploma in Information Technology -

Ambition Institute of Technology

10th -

CBSE Board

Master of Science - Information Security

IGNOU

PGDIS -

IGNOU

BSc. IT -

Kalinga University
Anmol Singh