Summary
Overview
Work History
Education
Certifications Awards
Skills Experience
Personal Information
Timeline
Generic

Nilesh Bakliwal

Ajmer

Summary

Nilesh Bakliwal is Solution Delivery Manager in Cyber and Strategy Risk Services group within Deloitte Risk & Financial Advisory having specialization in designing and implementing Splunk architecture for both on-premises and AWS/Azure Cloud environments, as well as automating the ingestion of logs from various AWS accounts and Azure subscriptions into the SIEM platform.
He has more than 11+ years of experience in the field of Information Technology which also includes skills in the Unix/Linux system programming, administration, and AWS/Azure Cloud technologies and HPE Arcsight implementation, setting up Splunk ITSI and ES, and Cribl and managing Security Operations and Splunk architect for one of the largest Oil and Gas company client and have experience of managing 20+ members.

Overview

12
12
years of professional experience

Work History

Solution Delivery Manager

Deloitte USI
Gurugram
06.2023 - Current
  • Leading Logging and Monitoring team for one of the hospitality industry and working with various application and infrastructure teams, stakeholders to understand the tech stack, identify the security gaps with the help of Threat model team, define and prioritize various security use cases for top-tier business critical applications and map them to MITRE/CAPEC framework.
  • Leveraging Splunk SIEM solution for onboarding data from various log sources, data normalization compliant with Splunk CIM data model, creating new correlation rules to monitor the gaps identified, fine-tune the use cases to eliminate false positives, create dashboards/reports and develop playbooks for the identified use cases, etc

Senior Solution Delivery Lead

Deloitte USI
Gurugram
12.2020 - 05.2023
  • Assumed the role of Delivery Lead for a prominent Energy Resource company that had outsourced critical IT security functions, including Security Monitoring & Incident Response, Security Device Management, SIEM Engineering, and Splunk Architecture planning, designing and implementation.
  • Improving Cloud Security posture by utilizing native and 3rd party cloud security solutions such as AWS native services including Guard Duty, Security Hub, Config etc.; Azure Security policies, Defender AV; Carbon Black Cloud and Symantec Cloud Workload protection.
  • Use Search Processing language (SPL) for creating dashboards, views, alerts, reports and saved searches and customize dashboard visualizations using xml, css.
  • Expertise in extracting fields using regex and creating good Splunk queries.
  • Install and configure various Splunk premium apps and addons like Splunk ES and ITSI.
  • Enable Correlation Searches and populate and normalize data in ES.
  • While for ITSI created services, KPIs, glass tables, episode reviews and deep dives.
  • Ingesting AWS Cloudtrail and Cloudwatch logs in Splunk.
  • Ingesting sample logs in Splunk for demo purposes through eventgen.
  • Configuration of Splunk data inputs by understanding various parsing parameters like index, source, source type, index sizes, index locations, read/write timeout values, line breaks, event breaks, time formats etc during index-time.
  • Develop customized application configurations in Splunk to parse, index multiple types of log format across all application environments.
  • Manage Splunk Enterprise licenses.
  • Develop Splunk indexes and manage their retention lifecycle.

Linux/Splunk Admininstrator

08.2013 - 03.2016
  • Linux Admin: Major flavors of Linux (RedHat, CentOS)
  • Installation, Administration, Troubleshooting, of the servers
  • Memory and disk space management
  • Patching and upgradation of OS
  • Configuration of Apache, postfix and various other services
  • Restart the servers and applications as per requirements
  • Good hands on with monitoring and alerting tools (Nagios and Splunk) Configuration, customization, maintenance, upgradation to new version, Configuring Host and Service checks, monitoring Threshold Management
  • Bigip F5/Nginx LB Tasks creation of VIP, pools and manages certificate profiles, basic editing of iRule, Upgrades
  • Server Provisioning Server Installation through Puppet/Foreman
  • Patching through mcollective/ansible
  • RHEL Upgradation through mcollective/ansible
  • Virtualization in Proxmox/RHEV Virtual Host Creation & Cloning
  • VLAN tagging
  • Resources maintenance of virtual servers
  • Python and shell scripting.

Incident Management/Alert Monitoring

02.2012 - 07.2013
  • Worked as a L1 support executive in Incident Management, alert monitoring, Change Management, Release Management, ITIL processes
  • Functional knowledge of Jira ticketing tool and Confluence documentation tool.

Splunk Administrator/Architecture/Developer

04.2016
  • Highly skilled in Splunk to build, configure and maintain different environments and in-depth knowledge of log analysis generated by linux Operating Systems
  • Install and monitor Splunk Forwarders on linux servers
  • Use Search Processing language (SPL) for creating dashboards, views, alerts, reports and saved searches
  • Expertise in extracting fields using regex and creating good Splunk queries
  • Customize dashboard visualizations using xml, css
  • Install and configure various splunk inbuilt apps like Palo Alto, Dmarc, Fireye and various others
  • Configuration of Splunk data inputs by understanding various parsing parameters like index, source, source type, index sizes, index locations, read/write timeout values, line breaks, event breaks, time formats etc during index-time
  • Skilled in deploying, configuring, administering and upgrade of Splunk servers (indexers, search heads) and forwarders
  • Develop customized application configurations in splunk to parse, index multiple types of log format across all application environments
  • Manage Splunk Enterprise licenses
  • Develop Splunk indexes and manage their retention lifecycle
  • Create roles for the application and app sharing permissions for the different roles
  • Optimized the search performance of Splunk queries and reduced the time for loading the dashboards
  • Extracted complex Fields from different types of Log files using Regular Expressions
  • Experience in setting up dashboards for senior management and production support- required to use SPLUNK
  • Fixing splunk internal errors/bugs
  • Also developed dashboards in Appdynamics using various metrics.

Education

Higher Secondary (12th) - Science Stream

Modi Public School
01.2006

Secondary School Certificate (10th) -

St. Paul Senior Secondary School
01.2004

Bachelor of Electronics & Telecommunication - Electronics and Telecommunications

Jaipur Engineering College and Research Center, Jaipur

Certifications Awards

  • ITIL, 2012
  • Red Hat Certified Engineer, 2014
  • Python-Basics, 2015
  • RHEV, 2016
  • OpenStack, 2016
  • Splunk User Certified, 2017
  • Splunk Power User Certified, 2017
  • Best Team Award, 2014
  • Best Team Award, 2016
  • Technical Excellence in Splunk, 2017
  • On the Spot Award for successful Splunk Upgrade, 2018
  • Successfully completed Intellipaat Splunk developer and administrator training, 2018
  • Lean Bronze certified for giving SIP (service improvement plan) in Splunk, 2018
  • Online Docker Training, 2019
  • Star of the Month Award in Accenture, 2019
  • Azure Fundamentals (AZ-900) training, 2020

Skills Experience

Around 8.6+ years of experience in the field of Information Technology which includes skills in the Unix/Linux system programming, administration, ITIL, and around 6 years in configuring, implementing and supporting Splunk Infrastructure across Linux and developing splunk dashboards and reports as a site reliability Engineer (SRE)., RHCSA/RHCE, RHEV, OpenStack, Splunk Certified User, Splunk Certified Power User, Splunk Certified Admin from Intellipaat, ITIL Foundation, Team Lead, 3, Successfully completed various projects., Unix/Linux System Administrator, 6, RHEL5.8, RHEL6, RHEL7, Unix, CentOS, Ubuntu, Open BSD, Nagios, Splunk Enterprise 6.x, Splunk Enterprise 7.x, Bitbucket, svn, Git, Puppet, BigipF5, Nginx, Proxmox, RHEV, AppDynamics, Strong installation, configuration and troubleshooting skills, Dependable and strong team player, Can provide visionary efforts to the projects, Quick Learner, Incident Management/Alert Monitoring, 02/2012, 07/2013, Worked as a L1 support executive in Incident Management, alert monitoring, Change Management, Release Management, ITIL processes. Functional knowledge of Jira ticketing tool and Confluence documentation tool., Linux/Splunk Administrator, 08/2013, 03/2016, Major flavors of Linux (RedHat, CentOS). Installation, Administration, Troubleshooting, of the servers. Memory and disk space management. Patching and upgradation of OS. Configuration of Apache, postfix and various other services. Restart the servers and applications as per requirements. Good hands on with monitoring and alerting tools (Nagios and Splunk). Configuration, customization, maintenance, upgradation to new version, Configuring Host and Service checks, monitoring Threshold Management. Bigip F5/Nginx LB. Tasks creation of VIP, pools and manages certificate profiles, basic editing of iRule, Upgrades. Server Provisioning. Server Installation through Puppet/Foreman. Patching through mcollective/ansible. RHEL Upgradation through mcollective/ansible. Virtualization in Proxmox/RHEV. Virtual Host Creation & Cloning. VLAN tagging. Resources maintenance of virtual servers. Python and shell scripting., Splunk Administrator/Architecture/Developer, 04/2016, current, Highly skilled in Splunk to build, configure and maintain different environments and in-depth knowledge of log analysis generated by linux Operating Systems. Install and monitor Splunk Forwarders on linux servers. Use Search Processing language (SPL) for creating dashboards, views, alerts, reports and saved searches. Expertise in extracting fields using regex and creating good Splunk queries. Customize dashboard visualizations using xml, css. Install and configure various splunk inbuilt apps like Palo Alto, Dmarc, Fireye and various others. Configuration of Splunk data inputs by understanding various parsing parameters like index, source, source type, index sizes, index locations, read/write timeout values, line breaks, event breaks, time formats etc during index-time. Skilled in deploying, configuring, administering and upgrade of Splunk servers (indexers, search heads) and forwarders. Develop customized application configurations in splunk to parse, index multiple types of log format across all application environments. Manage Splunk Enterprise licenses. Develop Splunk indexes and manage their retention lifecycle. Create roles for the application and app sharing permissions for the different roles. Optimized the search performance of Splunk queries and reduced the time for loading the dashboards. Extracted complex Fields from different types of Log files using Regular Expressions. Experience in setting up dashboards for senior management and production support- required to use SPLUNK. Fixing splunk internal errors/bugs. Also developed dashboards in Appdynamics using various metrics.

Personal Information

  • Date of Birth: 08/01/88
  • Nationality: Indian
  • Marital Status: Married

Timeline

Solution Delivery Manager

Deloitte USI
06.2023 - Current

Senior Solution Delivery Lead

Deloitte USI
12.2020 - 05.2023

Splunk Administrator/Architecture/Developer

04.2016

Linux/Splunk Admininstrator

08.2013 - 03.2016

Incident Management/Alert Monitoring

02.2012 - 07.2013

Higher Secondary (12th) - Science Stream

Modi Public School

Secondary School Certificate (10th) -

St. Paul Senior Secondary School

Bachelor of Electronics & Telecommunication - Electronics and Telecommunications

Jaipur Engineering College and Research Center, Jaipur
Nilesh Bakliwal