SOC Analyst with 3.5 years of Experienced in SIEM tuning, audit support, and reducing false positives through analytical techniques. Experience in monitoring, alert triage, log analysis, and threat response. I am skilled in handling enterprise environments involving AWS, Azure, firewalls, EDR, and VPNs. Proficient in advanced phishing investigations, threat hunting, and incident response. I am known for improving alert accuracy, developing SOPs, and mentoring junior analysts.
Overview
3
3
years of professional experience
1
1
Certification
Work History
SOC Engineer
HTC Global services
Chennai, Tamil Nadu, India
04.2023 - Current
(Currently deployed at client location, providing end-to-end support for alert investigation and incident handling across SIEM and EDR platforms)
Hands-on experience with SIEM tools such as Sumo Logic, Splunk, QRadar and Microsoft sentinel.
Monitoring the logs, unauthorized traffic, and policy update monitoring system activities in Endpoint and Firewall Devices
Implement SIEM tools and Optimized SIEM performance with regular tuning and configuration adjustments tailored to organizational needs
Managed and optimized SIEM solutions by implementing log collection, creating fine tuning queries and developing custom use cases.
Threat Detection & Log Analysis: Analyzed firewall, proxy, endpoint, and syslog data to detect anomalies; successfully identified and mitigated multiple phishing and brute-force attacks
SOAR Playbook Automation: Designed automated playbooks for phishing and malware alerts, reducing manual effort.
Conducted phishing investigations using sandbox analysis, header inspection, and threat intel tools.
Cloud Security Monitoring: Implemented and fine-tuned detection rules for Azure AD, O365, and AWS and Monitored AWS IAM and Azure AD for credential misuse and suspicious account activity.
Threat Intelligence Integration: Integrated threat feeds and correlated Indicators of Compromise (IOCs) with client logs, improving proactive detection of emerging threats.
Created weekly incident summary reports and SOPs for high-fidelity alerts.
Mentored new analysts in phishing analysis, IOC extraction, and playbook usage.
Client Reporting & Communication: Delivered detailed incident reports, dashboards, and executive summaries to clients, earning client appreciation for clear and actionable insights.
Recognized by clients for proactive threat hunting and log analysis, helping identify and mitigate critical vulnerabilities before exploitation.
Received client appreciation for detecting and responding to security incidents within SLA, reducing potential impact.
SOC Analyst Internship
Ernst and Young(EY)
Chennai, Tamil Nadu, India
06.2022 - 01.2023
Monitored and triaged security alerts in real-time using Splunk and IBM QRadar across multiple clients.
Conducted firewall, DNS, proxy, and endpoint log analysis to detect potential indicators of compromise (IOCs) and lateral movement.
Performed vulnerability assessments using Nessus and Nmap and reported high-risk findings to the remediation team.
Assisted in phishing investigations by analyzing suspicious emails, decoding URLs, and extracting malicious payloads from attachments.
Engaged in blue-team activities such as IOC enrichment using VirusTotal, AbuseIPDB, and WHOIS lookups.
Gained hands-on experience in ticketing tools like ServiceNow and JIRAfor incident lifecycle tracking.
Collaborated with senior analysts to tune SIEM rules, reducing false positives and enhancing alert quality.
Education
Bachelor of Science -
University of Madras
Chennai, Tamil Nadu
04.2021
Skills
SIEM Tools: Splunk, Sumo Logic, QRadar, CyberStellar, Microsoft sentinel