Dynamic Security Analyst with proven expertise at Accenture in triaging alerts and enhancing incident response efficiency. Skilled in SIEM tools like QRadar and Splunk, I excel in threat validation and escalation management. My proactive approach and meticulous documentation have significantly improved operational continuity and reduced false positives in security operations.
Overview
4
4
years of professional experience
Work History
Security Analyst
Accenture
08.2022 - 01.2026
Triaged and analyzed alerts in QRadar across AWS, Azure, and on-prem environments.
Investigated endpoint alerts in Cortex XDR analyzing causality chains, behavioral indicators, process executions, and file reputation verdicts.
Validated alerts by reviewing logs, user activity, IOC details, and event timelines, ensuring accurate incident assessment.
Contained threats by resetting passwords and locking accounts, reducing potential impact on systems.
Escalated true positives to L2/L3 with complete evidence (logs, IOCs, screenshots, timeline).
Documented incident handling steps in Service Now to maintain consistency and support audit readiness.
Delivered accurate shift handovers to enhance continuity and minimize repeated triage efforts.
SOC Analyst
Persistent Systems Limited
12.2021 - 07.2022
Monitored and triaged 50+ alerts daily in Splunk during rotating 24/7 shifts to ensure timely incident response.
Investigated malware-related alerts using CrowdStrike Falcon (process analysis, user session checks).
Analyzed firewall, proxy, VPN, and IDS logs to validate alert severity and minimize false positives.
Achieved SLA compliance for L1 alerts through prompt triage and organized ticket updates.
Escalated verified incidents with clear evidence, improving L2 investigation efficiency.
Executed responder actions, including credential resets and account disablements, to mitigate security threats.
Documented shift logs to ensure seamless transitions between teams and maintain operational continuity.
Education
BSc - MPCs
Satavahana University
Karimnagar
01.2018
Skills
SIEM
QRadar
Splunk
Cortex XDR
CrowdStrike Falcon
EDR/XDR
Log Sources
Firewall
Proxy
IDS/IPS
Active Directory
Office 365
Security Operations
Incident Response
Alert Triage
Log Analysis
Endpoint Investigation
Network Security Monitoring
Threat Validation
Threat Intelligence
IOC Validation
Threat Intel Feeds
MISP
ThreatConnect
Cloud Security
AWS
Azure
Windows
Linux
VPN
Ticketing Systems
ServiceNow
Jira
Projects
Full Attack Chain Investigation - Tempest, Investigated a compromised workstation through SIEM log analysis, identifying malicious process executions and extracting IOCs for correlation. Verified file hashes on VirusTotal, mapped activity to MITRE ATT&CK, and summarized findings in a NIST-aligned incident report. Threat Actor Campaign Analysis - Boogeyman Series (1, 2, 3), Analyzed multi-stage attack campaigns by correlating SIEM events across systems and mapping attacker TTPs to MITRE ATT&CK. Built a comprehensive incident timeline showing attacker evolution and documented escalation procedures for SOC response.