Summary
Overview
Work History
Education
Skills
Certification
Accomplishments
Languages
Custom
Timeline
Generic

Kalpit Mathur

Summary

Results-driven Security Engineer with 3 years of experience in SIEM and Detection Engineering. Designed and implemented SIEM architectures, onboarded log sources, and developed custom parsers and advanced detection logic. Proficient in deploying SIEM infrastructure, optimising log pipelines, tuning detections, and automating incident response across both on-premises and cloud environments.

Overview

1
1
Language
1
1
Certification
3
3
years of professional experience

Work History

Security Engineer

UltraViolet Cyber, Inc.
Hydrabad, India
08.2025 - Current
  • Lead migration of detection content from Splunk Enterprise Security to SentinelOne AI SIEM.
  • Onboard enterprise log sources into SentinelOne AI SIEM via syslog, APIs, connectors, and integrations to enhance security monitoring capabilities.
  • Design, develop, maintain custom SentinelOne detection content using PowerQuery queries.
  • Support Splunk Enterprise implementations using log integration parsers, searches, dashboards, and use cases.
  • Improve security visibility by integrating and validating telemetry from enterprise security platforms.
  • Improve event visibility and normalisation accuracy by resolving ingestion parsing and data quality issues.
  • Develop and maintain custom parsers for field extraction, normalisation, and enrichment to improve data accuracy and usability.
  • Develop dashboards to improve data monitoring, enhance detection documentation, and streamline onboarding and validation procedures.

SECURITY ENGINEER

QOS Technology Pvt Ltd
Mumbai
04.2025 - 08.2025
  • Streamlined Splunk deployment and management across Linux and Windows environments, ensuring robust data collection and indexing.
  • Utilized syslog, agents, APIs, and custom scripts to integrate multiple log sources including firewalls, Windows, Linux, Azure, AWS, AD, WAF, Office 365, switches, and routers.
  • Enhanced accuracy in log processing through the standardization of data ingestion with custom parsers.
  • Developed and maintained dashboards to enhance proactive threat detection.
  • Conducted regular Splunk infrastructure health checks and developed dashboards to monitor system performance.
  • Ensured endpoint protection through effective CS EDR management.
  • Configured secure access protocols to support role-specific functionality in Splunk.
  • Maintained system integrity through proactive issue resolution.
  • Created custom security reports and visualisations to improve executive and operational visibility.
  • Provided clear updates on security improvements to executive team.

SIEM ENGINEER - SENIOR SECURITY ANALYST

Ernst & Young Private Limited LLP
Mumbai
10.2023 - 04.2025
  • Configured and refined Splunk components such as Search Head, Indexers, Heavy Forwarders, and Universal Forwarders for Linux and Windows.
  • Streamlined data ingestion by integrating log sources from firewalls, Windows, Linux, Azure, AWS, AD, WAF, and Office 365.
  • Optimised SIEM performance through configuration and maintenance of NGINX and HAProxy load balancers, ensuring reliable data flow.
  • Conducted Splunk infrastructure health checks and developed monitoring dashboards, enabling proactive identification of performance issues.
  • Created and managed custom dashboards for real-time insights, enhancing threat detection.
  • Developed use cases to enhance proactive threat detection.
  • Identified and addressed vulnerabilities, providing senior management with strategic briefings on security enhancement initiatives.
  • Ensured data confidentiality through effective role-based access control.
  • Documented onboarding SOPs and automated incident response reporting to boost operational efficiency.

L1 SOC ANALYST

ASPL Info Services Private Limited
Bangalore
03.2023 - 10.2023
  • Triaged and analysed incoming alerts using Splunk, optimising detection and reducing false positives.
  • Monitored and enforced security policies to ensure adherence to industry standards and mitigate security risks.
  • Designed and maintained custom dashboards for real-time security visibility.
  • Onboarded and monitored event sources, ensuring accurate data collection.
  • Prepared incident response reports summarising security activities to inform stakeholders and guide future security measures.
  • Deployed Splunk Enterprise Security in a lab environment, demonstrating hands-on expertise.

Education

B.Tech - Computer Science

Jodhpur Institute of Engineering & Technology
Jodhpur
01-2022

Skills

SIEM Platforms

  • SentinelOne AI SIEM
  • Splunk Enterprise
  • Microsoft Azure Sentinel
  • Google Chronicle
  • SPL (Splunk Search Processing Language)
  • SIEM Engineering
  • SIEM Configuration

Splunk Administration

  • Log onboarding
  • Log parsing
  • Data integration
  • Log analysis
  • Detection Tuning
  • Threat detection
  • Data visualisation
  • Deployment of Splunk Clusters

Endpoint protection

  • SentinelOne EDR
  • HAProxy
  • NGINX
  • Windows & Linux Administration
  • Azure AD
  • Identity & Access Management (IAM)
  • Python
  • Shell scripting
  • Cribl

Certification

  • Level 1: Cribl Certified User
  • Microsoft Security, Compliance, and Identity Fundamentals SC-900
  • CCNAv7: Introduction to Networks
  • Certified SOC Expert
  • Introduction to Enterprise Security
  • Cyber Security and Ethical Hacking
  • Windows Penetration Testing Essentials

Accomplishments

  • EY Client Extraordinary Award
  • EY Cyber Security Bronze Badge

Languages

English
Proficient
C2

Custom

LinkedIn, https://www.linkedin.com/in/kalpit-mathur-jodhpur/

Timeline

Security Engineer

UltraViolet Cyber, Inc.
08.2025 - Current

SECURITY ENGINEER

QOS Technology Pvt Ltd
04.2025 - 08.2025

SIEM ENGINEER - SENIOR SECURITY ANALYST

Ernst & Young Private Limited LLP
10.2023 - 04.2025

L1 SOC ANALYST

ASPL Info Services Private Limited
03.2023 - 10.2023

B.Tech - Computer Science

Jodhpur Institute of Engineering & Technology
Kalpit Mathur