Summary
Overview
Work History
Education
Skills
Certification
Websites
Timeline
Generic

Saiprashanth Sivakumar

Chennai

Summary

A dynamic security professional with over 4.5+ years of experience, having a demonstrated history of working in the information technology and services industry, skilled in SOC deliverables and Defender for Endpoints as an SME.
Currently seeking a challenging and varied position that will enable me to capitalize on sound technical and design expertise, with opportunities for personal and professional growth in the field of cybersecurity.

Overview

5
5
years of professional experience
1
1
Certification

Work History

Senior Incidence Response Analyst (IT Analyst)

TCS
Chennai
09.2024 - Current
  • Lead the investigation of cybersecurity incidents, including malware outbreaks, phishing attacks, data breaches, and unauthorized access attempts.
  • Perform detailed root cause analysis, assess the impact, and recommend containment, eradication, and recovery strategies.
  • Coordinate with cross-functional teams to handle incidents effectively, ensuring minimum business disruption.
  • Continuously monitor SIEM and other security platforms (MDE) to detect and respond to threats in real time.
  • Develop, review, and update incident response playbooks to ensure consistent and efficient handling of incidents.
  • Implement automation using SOAR (Security Orchestration, Automation, and Response) tools to streamline repetitive tasks and improve response time.
  • Collaborate with the security awareness team to promote phishing simulations and other training programs.
  • Creating of SOP's based on the team requirement and plans.

Endpoint Security Engineer (MDE)

TCS
Chennai
07.2022 - 09.2024
  • As a Defender SME, I monitored and reported health checks for the devices daily (Servers) and monthly (Workstations), or as per client request.
  • Creating custom detection rules for critical cyber threats and Suppression of False positive alerts.
  • Assisted Clients for troubleshooting the inactive/misconfigured devices with Microsoft.
  • Blocking the IOCs, as per threat advisories, and purging of phishing emails reported by the users.
  • Creation of Phishing Simulation for User Awareness.
  • Creation of Microsoft cases for various issues and troubleshooting for the remediations.

Implementation/Migration:

  • Migrated devices from other endpoint security tools to MDE.
  • Implemented MDI for the clients to detect lateral movement alerts.
  • Created custom detection rules to detect and contain emails from the latest phishing campaigns.
  • Performed assessments on MDO and MDE to enhance the security posture.
  • Configured ASR Rules to help in mitigating malware infection and limiting actions that could allow adversaries to exploit vulnerabilities or perform malicious actions on endpoints.

SOC Analyst L2

TCS
chennai
03.2022 - 07.2022
  • Alert Analysis and incident investigations through Sentinel and Q-radar
  • Escalating Critical incidents to L3 for further analysis and closure of the incidents.
  • Phishing Analysis on User reported mails and Blocking of the Necessary IOCs for the same.
  • Monitoring & Analysis on User sign-in activities through Cloud-app and correlating with other Microsoft tools like Sentinel and MDE.
  • Working on MDR (Detection & Response ) activities through MDE which includes devices isolation, Quarantining of suspicious files, Running full AV scan and Initiating Live Response.
  • Protecting User Identities by changing the password, reseting MFA and Revoking sessions of the users.

SOC Analyst L1

Wipro
Chennai
12.2019 - 02.2022
  • Real Time Alert Monitoring and Incident Investigations using SIEM Tools (Q-radar & Sentinel).
  • Monitoring of User sign-in activities using Microsoft Cloud-app Tool and correlation with tools.
  • Alert Analysis and Detection & Response using MDE tool.
  • Phishing & Malware Analysis through the user reported mails.
  • Creation of Phishing simulation for user awareness though defender for endpoints.

Education

Bachelor of Technology - Electronics & Communication

Crescent Institute of Science & Technology
Chennai, TN
2019

Mtech - Cybersecurity

SRM Institute of Science And Technology
Chennai

Skills

Technical Skills:

  • Incident triage, analysis, and escalation
  • Root cause analysis and remediation
  • Real-time threat hunting and investigation
  • Malware analysis
  • Event correlation and alert analysis
  • Familiarity with MITRE ATT&CK Framework
  • NIST Frameworks
  • Incident response using EDR tools for threat containment and investigation
  • Implementing and managing ASR rules in Microsoft Defender for Endpoint

Soft Skills:

  • Ability to present technical information to non-technical stakeholders clearly
  • Writing clear, detailed post-incident reports
  • Coordinating tasks and timelines for incident resolution and post-incident activities

Certification

  • Certified Ethical Hacker (EC-Council)
  • Certified Security Analyst (EC-Council)
  • SC-200 -Security Operations Analyst (Microsoft)
  • AZ-500 -Microsoft Azure Security Technologies (Microsoft)
  • MS-500-Security Administration (Microsoft)
  • Comptia Cysa+ (Cybersecurity Analyst)

Timeline

Senior Incidence Response Analyst (IT Analyst)

TCS
09.2024 - Current

Endpoint Security Engineer (MDE)

TCS
07.2022 - 09.2024

SOC Analyst L2

TCS
03.2022 - 07.2022

SOC Analyst L1

Wipro
12.2019 - 02.2022

Bachelor of Technology - Electronics & Communication

Crescent Institute of Science & Technology

Mtech - Cybersecurity

SRM Institute of Science And Technology
Saiprashanth Sivakumar