To associate myself with a progressive and dynamic organization that gives me an opportunity to seek a challenging career and to be a part of a team that works towards steady growth.
Overview
13
13
years of professional experience
5
5
Certification
Work History
Technical Specialist
IBM India Pvt Ltd
12.2017 - Current
Responsibilities in Current Organization- IBM India Pvt Ltd
PROJECT AT IBM : Cyber Fusion Center SOC Analyst – Dedicated Project of Banking Industry
Handling SOC monitoring tool Splunk alerts which are integrated with multiple log sources like EDR – CrowdStrike, Tanium, Network alerts, Proofpoint, Zscaler, windows logs, Linux logs.
Analysis of Splunk notables through Search Processing Language (SPL).
Analysis of EDR notables through CrowdStrike and Tanium consoles.
Handling XSOAR cases and creation of XSOAR tickets which needs to be escalated to Incident Response team.
Handling Email Security – Proof point cases related to emails of Phishing, Vishing, Smishing
Monitoring Zscaler console.
Monitoring network traffics from Stealthwatch console.
PROJECT AT IBM : Endpoint Detection and Response (EDR) Solution Admin – Dedicated Project
NATURE OF WORK : Level 3 (L3) Support
SCOPE OF WORK : Handling Endpoint Detection and Response (EDR) Tool – Tanium
PERIOD : June 2022 to August 2024
RESPONSIBILITIES:
Managing EDR product Tanium sensors across all endpoints which includes workstations and servers.
Deploying Tanium sensors agents on endpoints as a part of compliance.
Configuring policies on endpoints based on business requirement.
Securing the environment from zero-day attacks by updating private threat intel with the highly reputation Indicators of Compromise (IOCs).
Managing the on-going incidents occurred and helping respective teams for resolutions.
Upgrading Tanium sensor versions to the latest versions released to market to be secured from non-vulnerabilities.
Creation of hypothesis based on the flow of incidents received.
Creating threat hunting queries in Tanium.
Indulging in presenting the monthly view of Endpoint Security solutions to the Customer.
Monitoring Microsoft Sentinel (SIEM) and Tenable Vulnerability management tool.
PROJECT AT IBM : Endpoint Threat Management Team – Dedicated Project
NATURE OF WORK : Level 3 (L3) Support
SCOPE OF WORK : Handling Antivirus Technologies (McAfee EPO 5.3.1, 5.9.1 & 5.10 Update11/Agent/VSE/DLP/HIPs/Endpoint Security - ENS)
PERIOD : December 2017 to May 2022
RESPONSIBILITIES:
Installing and configuring McAfee ePolicy Orchestrator 5.3.1 & 5.9.1 on 18 Business Units which has 18 McAfee ePO servers with Embedded/dedicated SQL servers.
Upgrading McAfee ePolicy Orchestrator from current to latest version as per BU requirements for example from 5.3.1 to 5.9.1 and 5.9.1 to 5.10.x.
Migration of McAfee ePolicy Orchestrator application and database from older windows box to new windows box based on supported platform and BU requirement.
Managing 4000+ servers with McAfee Agent 5.6.x, VSE 8.8 Patch 15, Endpoint Security Threat Prevention 10.7.x.
Fine tuning McAfee Agents, VSE & ENS policies from EPO as per business requirement and best practice from Security perspective.
Installing latest versions on McAfee products extensions and check-in in master repository.
Migration of McAfee VirusScan Enterprise to Endpoint Security product from ePO and setting up mirror policies.
Handling and working on High Severity Tickets (P1) dedicatedly.
Handling escalations with respect to Endpoint Protection technologies.
Presenting Monthly compliance and progressions to the customers.
Working with 4 engineers of Endpoint Threat Management Team to achieve agreed Service Level Management and improving technical skills with 9/5 support.
Creating Standard Operation Procedure (SOP) documents for all activities.
Analyzing Virus logs for a week/month and provide the best practice solutions to avoid infections in the environment.
Senior Security Engineer - ITO Service Delivery
Hewlett Packard Enterprise
04.2016 - 11.2017
Responsibilities in Previous Organization- Hewlett Packard Enterprise (New Name – DXC Technology)
PROJECT AT HPE : Infra Lead for 2 accounts in Endpoint Threat Management Team - Shared
NATURE OF WORK : Level 3 (L3) Support and Team Lead
SCOPE OF WORK : Handling Antivirus Technologies (McAfee EPO 5.3.1/Agent/VSE/HIPs, Trend Micro OfficeScan/Deep Security Manager & Agent)
PERIOD : April 2016 to November 2017.
RESPONSIBILITIES:
Installing and configuring McAfee ePolicy Orchestrator 5.3.1 and Agent Handler applications on the servers.
Managing 2000 servers with McAfee VSE 8.8 Patch7 and HIPs 8.0 Patch7.
Fine tuning McAfee VSE & HIPs policies from EPO as per business requirement and best practice from Security perspective.
Installing latest versions on McAfee products extensions and check-in in master repository.
Handling and working on High Severity Tickets (P1) dedicatedly.
Handling escalations with respect to Antivirus technology.
Presenting Monthly compliance and progressions to the customers.
Driving team of 7 engineers to achieve agreed Service Level Management and improving technical skills with 24/7 support.
Creating Standard Operation Procedure (SOP) documents for all activities.
Installing and configuring Trend Micro OfficeScan and Deep Security Manager latest versions in cluster environment.
Fine tuning Deep Security Agent (Anti-Malware/IPS) policies for servers.
Analyzing Virus logs for a week/month and provide the best practice solutions to avoid infections in the environment.
Creation and maintenance of each account’s documents to have a successful ISO audit.
Implementing and deploying Trend Micro Deep Security Agents on DMZ network.
Senior Project Engineer
Wipro InfoTech Pvt Ltd
08.2011 - 04.2016
Responsibilities in Oldest Organization- Wipro InfoTech
Senior Lead, Software Architecture (Automation Architect) at Kyndryl India Pvt Ltd (IBM India Pvt. Ltd.)Senior Lead, Software Architecture (Automation Architect) at Kyndryl India Pvt Ltd (IBM India Pvt. Ltd.)