Summary
Overview
Work History
Education
Skills
Key Technologies Expertise
Languages
Key Deliverables
Personal Information
Awards
Timeline
Generic

RAJESH KUMAR ANBURAJAN

Chennai

Summary

Experienced and certified Cybersecurity Technical Lead with over 10 years of proven success in Security Operations, Threat Management, and Automation. Adept at leading end-to-end implementations of SIEM and SOAR platforms including Cortex XSOAR, XSIAM, IBM QRadar, Splunk, and ServiceNow. Demonstrated expertise in developing advanced playbooks, automating incident response, integrating threat intelligence, and optimizing SOC operations. Skilled in Python scripting, cloud security (AWS & Azure), and cross-functional collaboration across global teams. Recognized for delivering scalable solutions, reducing manual effort, and enhancing threat detection and response efficiency. A proactive leader with a strong foundation in Agile/Scrum methodologies and a commitment to continuous innovation in cybersecurity.

Overview

10
10
years of professional experience

Work History

Senior Engineer-XSOAR

Anlage Infotech Pvt Ltd
01.2025 - Current

I managed incident response and threat detection across multiple SIEM and SOAR platforms, including Cortex XSOAR, XSIAM, IBM SOAR, QRadar, Splunk, Cribl, and ServiceNow. I developed advanced automations and response workflows to streamline phishing detection, investigation, and remediation. I designed and implemented over 10 Cortex XSOAR playbooks using Python to automate alert triage, threat enrichment, IOC management, and ticket orchestration. Additionally, I developed integrations with tools such as Microsoft Defender, Azure AD, and Microsoft Graph API for real-time metadata extraction and incident correlation. I automated repetitive tasks such as patch validation, IOC enrichment, and alert tagging to improve operational efficiency. I integrated automation with Azure Security Center, AWS, and Microsoft Defender to enhance cloud visibility, enforce policies, protect identities, and detect anomalies. I also customized dashboards and email analytics widgets in XSOAR to support phishing pattern recognition and executive-level reporting. I improved monitoring by enhancing the performance of email metadata extraction and visualization tasks. As the on-call XSOAR automation support for CIC and TCO tenants, I handled daily triage, resolved bugs, and implemented performance improvements. I collaborated with cross-functional teams, including TI, TCO, CIC, and the global SOC, to implement automation aligned with organizational goals, and actively contributed to Agile/Scrum processes, supporting continuous delivery with a strong focus on quality and turnaround time.

Technical Lead

L&T Technology Services Limited
04.2023 - 01.2025

I conducted threat landscaping for client environments by identifying critical assets (Crown Jewels) and developing data flow architectures. I created over 60 threat-based use cases to enhance the organization's security posture. I integrated over 2,000 log sources with the IBM QRadar SIEM platform, monitored for event drops, and optimized EPS (10,000+) using a selective approach to increase visibility and reduce costs. I designed and implemented end-to-end SOC architecture using IBM QRadar SIEM and IBM QRadar SOAR, accounting for data volume, EPS, data retention policies, and geographical distribution. By refining over 100 use cases and identifying key conditions, I significantly reduced false positive alerts. I managed the setup of over 5,000 EDR agents, including policy creation, signature updates, and implementation of a high availability architecture. I developed over 50 playbooks and integrated various security tools (e.g., EDR, firewalls, threat intelligence, AD, HIPS) to automate incident response through Python scripting, minimizing manual ticket creation. I also automated the addition of Indicators of Compromise (IOCs) into firewalls, proxies, and EDR solutions using threat intelligence feeds, saving significant man-hours. I managed the Security Service Provider (MSSP) add-on, which enabled the management of multiple customers from a single dashboard while ensuring client data remained isolated. Additionally, I performed Vulnerability Assessment and Penetration Testing (VAPT), targeting mitigation of OWASP Top 10 vulnerabilities, and delivered comprehensive reports outlining effective risk mitigation strategies.

Assistant Manager – SOAR

LARSEN & TOUBRO LIMITED
10.2022 - 03.2023

I led incident response and threat detection across multiple SIEM and SOAR platforms, including Cortex XSOAR, XSIAM, IBM SOAR, QRadar, Splunk, Cribl, and ServiceNow. I created advanced automations and response workflows to streamline phishing detection, investigation, and remediation. I conducted threat landscaping for client environments by identifying critical assets (Crown Jewels) and developing data flow architectures. I developed over 60 threat-based use cases to strengthen the organization’s security posture. I integrated more than 2,000 log sources with the IBM QRadar SIEM platform, monitored for event drops, and optimized EPS (10,000+) using a selective approach to increase visibility and reduce costs. I designed and implemented end-to-end SOC architecture using IBM QRadar SIEM and SOAR, taking into account data volume, EPS, retention policies, and geographical spread. By refining over 100 use cases and identifying key conditions, I significantly reduced false positives. I managed the setup of over 5,000 EDR agents, including policy configuration, signature updates, and deployment of a high-availability architecture. I developed more than 50 playbooks and integrated a variety of security tools—such as EDR, firewalls, threat intelligence, Active Directory, and HIPS—to automate incident response using Python scripting, reducing manual ticket creation. I also automated the ingestion of Indicators of Compromise (IOCs) into firewalls, proxies, and EDR systems using threat intelligence feeds, saving substantial analyst time. Additionally, I managed the Security Service Provider (MSSP) add-on, enabling centralized management of multiple customers from a single dashboard while maintaining strict data isolation. I performed Vulnerability Assessment and Penetration Testing (VAPT), focusing on OWASP Top 10 vulnerabilities, and delivered comprehensive risk mitigation reports.

IT Analyst

Tata Consultancy Services Limited
09.2021 - 10.2022

I developed various automations and threat response mechanisms for high-level use cases within customer environments, leveraging SIEM and SOAR platforms in security operations centers. I conceptualized and implemented multiple automations and built numerous integrations with security tools such as EDR, firewalls, threat intelligence platforms, Active Directory, and HIPS. I automated the incident response and investigation processes in Cortex XSOAR from the ground up, and regularly shared requirements and enhancement suggestions to improve XSOAR’s effectiveness and monitoring capabilities. I also designed and implemented end-to-end SOC architecture using IBM QRadar SIEM and SOAR, taking into consideration factors such as data volume, EPS, data retention, and geographical distribution. As a cybersecurity analyst and the designated point of contact from TCS, I actively collaborated with the client to enhance and develop XSOAR functionalities. Additionally, I created and deployed multiple XSOAR playbooks to automate the incident investigation process and reduce repetitive manual tasks.

Senior Software Engineer

Accenture Solution private Limited
07.2019 - 07.2021

I coordinated with the team to streamline security operations and enhance incident response efficiency. I actively participated in use case ideation, contributing to the development of custom rules and alerts for proactive threat detection. I monitored and maintained system health to ensure the continuous and reliable operation of SIEM and SOAR platforms. I successfully managed relationships with overseas customers, addressing their security requirements and ensuring satisfaction. I conducted troubleshooting and resolved technical issues, minimizing downtime and preserving the integrity of security systems. I developed and implemented SOAR playbooks to automate incident response procedures, significantly reducing response times and increasing operational efficiency. Additionally, I collaborated with cross-functional teams to identify automation opportunities and reduce manual efforts. I also conducted training sessions for SOC personnel on the use of SOAR playbooks and automation tools, enhancing overall team proficiency.

Senior Software Engineer

Trans-neuron Technologies private Limited
10.2018 - 07.2019

I coordinated with the team to streamline security operations and improve incident response efficiency. I actively contributed to use case ideation, helping to develop custom rules and alerts for proactive threat detection. I monitored and maintained system health to ensure the continuous and reliable operation of SIEM and SOAR platforms. I successfully managed relationships with overseas clients, addressing their security requirements and ensuring high levels of satisfaction. I conducted troubleshooting and resolved technical issues, minimizing downtime and preserving the integrity of security systems. I developed and implemented SOAR playbooks to automate incident response procedures, significantly reducing response times and increasing operational effectiveness. Additionally, I collaborated with cross-functional teams to identify automation opportunities and minimize manual effort. I also conducted training sessions for SOC personnel on the use of SOAR playbooks and automation tools, enhancing overall team proficiency.

Software Engineer

Savvy Soft Technologies
10.2017 - 10.2018

I served as the Subject Matter Expert (SME) for NSDC (National Skill Development Corporation India), a central government client. My responsibilities included the implementation of PDF generation services and user service modules. I worked in a Scrum-based environment and also took on the role of Scrum Master. I was involved in creating user interfaces using HTML, CSS3, Bootstrap, and jQuery, and developed APIs using Node.js, MongoDB, and RESTful methods. Additionally, I performed manual and unit testing, bug fixing, and was responsible for identifying and creating comprehensive manual and unit test cases.

Software Engineer

Syncfusion Software Private Limited
09.2015 - 10.2017

I developed business processes using Kanban and Ribbon components and handled customer support queries related to the Syncfusion Ribbon component. I performed manual and unit testing, conducted bug fixing, and was responsible for identifying and creating detailed test cases. Additionally, I used Jira for bug tracking and SVN for source code version control.

Education

B.E - Computer Science And Engineering

Sree Sastha Institute of Engineering And Technology
04.2015

Higher Secondary School - Computer Science

Vijayanta Higher Secondary School
04.2011

Skills

  • SIEM
  • IBM QRadar
  • Sentinel
  • SOAR
  • IBM SOAR
  • XSOAR PALO ALTO
  • Forti SOAR
  • Splunk
  • Python
  • HTML
  • CSS
  • JavaScript
  • NodeJS
  • AWS
  • SQL
  • Postgres
  • Windows
  • Linux
  • EDR
  • TrendMicro
  • XDR
  • Vulnerability Assessment
  • Threat Intel
  • Unit Testing
  • BDD testing
  • Integration Testing
  • Sanity Testing
  • Cribl

Key Technologies Expertise

I possess extensive hands-on experience across a wide range of cybersecurity and IT technologies, specializing in Security Operations Center (SOC) implementation, incident response, and threat management. My core areas of expertise include:

SIEM & SOAR Platforms
  • Cortex XSOAR, Cortex XSIAM
  • IBM QRadar SIEM & SOAR
  • Splunk Enterprise Security
  • ServiceNow SecOps
  • Cribl LogStream
Security Automation & Scripting
  • Playbook development and custom integrations using Python
  • REST API integration across security platforms
  • Automation of incident triage, enrichment, remediation, and reporting
Email Security & Analytics
  • Microsoft Defender for Office 365
  • Microsoft Graph API for email metadata extraction and analysis
  • Automated email investigation and phishing remediation workflows
Cloud Security Platforms
  • Microsoft Azure Security Center
  • Azure AD, Microsoft Graph
  • Amazon Web Services (AWS) – Lambda, IAM, Security Hub integrations
Threat Intelligence & Detection
  • IOC ingestion, correlation, and blocking automation
  • Custom rule development for threat detection
  • Integration with EDR, firewall, proxy, and threat intel platforms
EDR and Endpoint Management
  • Integration and automation with tools like CrowdStrike, Microsoft Defender for Endpoint
  • Deployment and policy management for 5000+ endpoints
Agile/Scrum & DevOps
  • Active participation in Agile ceremonies
  • CI/CD pipeline integration for security automation updates
  • Use of Jira, Confluence, and Git for development tracking
Web/UI Development (Past Roles)
  • HTML, CSS3, Bootstrap, jQuery for UI interfaces
  • Node.js & MongoDB for API and backend development (NSDC & CNS projects)

Languages

English
Tamil
Malayalam

Key Deliverables

Key Deliverables
  • Cortex XSOAR Automation Framework: Delivered over 10 end-to-end automation playbooks in Cortex XSOAR for incident triage, threat enrichment, IOC management, and case orchestration, reducing manual efforts and improving response time by over 60%.
  • Phishing Incident Automation: Developed phishing detection, investigation, and remediation playbooks, including bulk email purge via CSV, auto-classification using Defender verdicts, and targeted campaign detection logic.
  • Integration Engineering: Built robust integrations with Microsoft Defender, Azure AD, Graph API, AWS, and other security tools to enhance SOC visibility and automate data collection and response workflows.
  • SOAR Monitoring & Support: Maintained performance and reliability of SOAR platforms with cron-based health check automation and daily on-call support for CIC and TCO tenants, including debugging and optimization of Graph API workflows.
  • Security Platform Implementation: Designed and implemented complete SOC architecture using IBM QRadar SIEM and SOAR, considering factors such as EPS, data retention, and client geo-distribution.
  • Cross-Functional Collaboration: Partnered with Threat Intelligence, Cloud, and SOC teams to identify automation opportunities and improve detection coverage, incident handling, and dashboard reporting.
  • Cloud Security Automation: Integrated automation with Azure Security Center and AWS for real-time incident correlation, patch validation, anomaly detection, and policy enforcement.
  • Customer Engagement & Techno-Commercial Support: Acted as point of contact for key global clients (e.g., L&T Defense, Meriplex, Bank Mandiri), delivering custom solutions, managing expectations, and preparing detailed techno-commercial proposals.
  • Software Development: Designed and developed full-stack applications and UI components using Node.js, MongoDB, HTML, Bootstrap, and jQuery; contributed to central government and telecom projects (NSDC, Cox Communications) with robust backend APIs and serverless architecture.

Personal Information

Awards

Awards & Recognitions
  • Best Performer Award – LTIMindtree
    Recognized for delivering advanced Cortex XSOAR automation solutions that significantly reduced incident response time and manual efforts across multiple client environments.
  • Client Appreciation – Bank Mandiri, L&T Defense, Meriplex
    Received direct recognition from global clients for providing impactful threat detection and response solutions and delivering high-quality automation workflows that enhanced SOC effectiveness.
  • Innovation in Security Automation – Anlage Infotech Pvt Ltd
    Honored for developing cutting-edge automation in phishing detection, email analytics, and cloud incident correlation using XSOAR, Microsoft Defender, and Azure integrations.
  • Spot Award – TCS
    Awarded for leading end-to-end implementation of IBM QRadar SIEM and SOAR architecture and serving as the single point of contact for security automation and integration requirements.
  • Excellence in Delivery – National Skill Development Corporation (NSDC)
    Recognized for successfully implementing PDF generation and user management services while performing dual roles in development and scrum management.

Timeline

Senior Engineer-XSOAR

Anlage Infotech Pvt Ltd
01.2025 - Current

Technical Lead

L&T Technology Services Limited
04.2023 - 01.2025

Assistant Manager – SOAR

LARSEN & TOUBRO LIMITED
10.2022 - 03.2023

IT Analyst

Tata Consultancy Services Limited
09.2021 - 10.2022

Senior Software Engineer

Accenture Solution private Limited
07.2019 - 07.2021

Senior Software Engineer

Trans-neuron Technologies private Limited
10.2018 - 07.2019

Software Engineer

Savvy Soft Technologies
10.2017 - 10.2018

Software Engineer

Syncfusion Software Private Limited
09.2015 - 10.2017

B.E - Computer Science And Engineering

Sree Sastha Institute of Engineering And Technology

Higher Secondary School - Computer Science

Vijayanta Higher Secondary School
RAJESH KUMAR ANBURAJAN