Experienced Security Engineer with a demonstrated history of working in IT Security, is seeking a challenging position that promotes learning and growth.
Overview
5
5
years of professional experience
5
5
years of post-secondary education
4
4
Certifications
Work History
Security Engineer 2 – Sky SIRT CSOC
Comcast India Engineering Center, Chennai
08.2023 - Current
Key Qualifications and Responsibilities
Incident Detection and Analysis: Investigated alerts related to endpoint security, such as malware infections, unauthorized access attempts, and system anomalies. Utilized EDR(CrowdStrike) & NDR(Darktrace) tools to analyze and remediate threats.
Root Cause Analysis: Perform root cause analysis to determine how endpoints were compromised and implement measures to prevent recurrence.
Phishing Incident Response: Lead investigations into phishing incidents, including identifying compromised accounts, analyzing attack vectors, and implementing effective remediation strategies.
Analyzed UBA data from Exabeam to detect and respond to abnormal user behaviors, such as excessive file access or unusual login patterns.
Worked on XSOAR automation enrichment and Finetuning Correlation rules in Splunk for false positive alerts.
Documented incident responses and contributed to the creation of knowledge base runbooks.
Security Analyst - Corporate Security SOC
Cognizant Technology Solutions
07.2019 - 08.2023
Key Qualifications and Responsibilities
Experienced in analyzing the offenses triggered in SIEM Tool (Qradar)and identifying the true and false positive offenses in it
Experienced in analyzing cloud-based alerts in Microsoft Defender for Cloud Apps (MDCA) & Prisma, malware analysis in Cisco AMP for Endpoints, Microsoft Defender and documented the evidence in ServiceNow
Performing dynamic malware analysis using Sandbox - Fire Eye AX, Anomali and OSINT tools
Finetuning rules in SIEM to avoid False positive offenses
Common Corporate SOC Mailbox monitoring, Phishing mail analysis
Handling IOCs and Adhoc requests
Maintained SLA in all the offenses handled
Worked on monthly project reports
Provided Knowledge transfer sessions to new team members.
Education
Master of Science - Cyber Forensics And Information Security
University of Madras
06.2019 - 05.2021
BCA - Computer Applications
Shri Shankarlal Sundarbai Shasun Jain College
06.2016 - 04.2019
Skills
SIEM – QRadar, Splunk
Endpoint Security – Cisco AMP, Microsoft Defender for Endpoints (MDE) and Microsoft Defender for Identity (MDI), Microsoft Azure, Falcon CrowdStrike, NDR – Darktrace, UBA - Exabeam
Privilege Access Management - CyberArk
Cloud – Palo Alto networks Prisma Cloud, MDCA
Web – Forcepoint Proxy, Cisco Umbrella, Firewall FMC
Internal CTI – ThreatStream Anamoli, Orbital
Threat Intelligence – IBM XForce, Anamoli, OSINT
Sandbox- Threat Grid, Trellix, FireEye AX
Vulnerability scanners – Nessus, Burpsuite
Packet Analyzer - Wireshark
Case Management – ServiceNOW, JIRA, BMC Remedy, Cortex XSOAR
Procurement Project Manager - Category Management at Comcast India Engineering CenterProcurement Project Manager - Category Management at Comcast India Engineering Center
Engineer 3 – Incident/Problem/Change Management at Comcast India Engineering Center LLPEngineer 3 – Incident/Problem/Change Management at Comcast India Engineering Center LLP