Summary
Overview
Work History
Education
Skills
Certification
Disclaimer
Timeline
Generic

Sathya Manikanta Gidugu

Hyderabad,Telangana

Summary

With over 6 years of experience in Information Security, I am currently serving as a Cyber Security Technologist in the Global Security Monitoring Operations Team, focusing on threat analysis, security monitoring, and operational management. I possess hands-on expertise in SIEM (Security Information and Event Management) tools, including IBM QRadar, Griffith, and Splunk for real-time event monitoring. Additionally, I have earned certifications in CEH, Ethical Hacking, and Information Security from NIELIT.
My responsibilities include proactive security monitoring and threat analysis, where I track and analyze security alerts and conduct in-depth incident analysis to detect and recognize attacks based on known signatures. I regularly prepare tailored daily, weekly, and monthly reports, create knowledge bases and dashboards, and ensure accurate, SLA-bound incident management.
In automation projects, I develop and optimize SOAR playbooks to automate security tasks, streamline workflows, and improve efficiency through debugging and cross-tool integration. As an Incident Commander, I lead high-priority incidents by coordinating response efforts, managing escalations, gathering critical information, and ensuring timely resolutions through cross-functional teamwork. I also collaborate on bug bounty case management, supporting proactive threat hunting by investigating, validating, and remediating vulnerabilities found in bug bounty reports. Additionally, I develop Standard Operating Procedures (SOPs) for new processes and alerts to ensure SOC operations remain consistent, efficient, and well-documented.

Overview

7
7
years of professional experience
1
1
Certification

Work History

Cyber Security Technologist

Uber Technologies Inc.
04.2020 - Current
  • Security Monitoring & Alert Response (SOAR): Utilize Splunk Phantom (SOAR) for real-time security monitoring, promptly acknowledging and addressing alerts within a 15-minute SLA. Monitored and responded to alerts from phishing, malware, data exfiltration, and cloud sources, including AWS Guard Duty.
  • Incident Case Management(Endpoint): Managed and triaged high-severity incidents, ensuring effective case handling from acknowledgment to resolution. Conducted initial acknowledgment, gathered critical incident details, and assessed impact to prioritize response efforts. Collaborated with relevant teams to escalate cases as needed.
  • Phishing Email Analysis: Analyzed phishing incidents reported via Gmail and G Suite using Splunk Phantom and internal tools to detect and mitigate malicious links and attachments.
  • Malware Detection: Investigated alerts from EDR tools (e.g., CrowdStrike, Sentinel One, Azure microsoft defender) to identify and respond to malware infections, assessing indicators of compromise (IoCs) and performing threat containment.
  • Data Exfiltration Monitoring: Handled suspicious data exfiltration alerts, leveraging SIEM logs and DLP tools to verify unauthorized data access, identify potential insider threats, and mitigate risks.
  • Cloud and Platform Security: Monitored AWS GuardDuty, GCP, and platform-specific detection alerts (SSH, AWS, GCP, and Linux commands) to ensure robust security across both cloud and on-premises environments. We manage AWS and GCP alerts, tracking user activities across these cloud platforms.
  • Data Analysis & Query Development (Query_builder): Built advanced queries for incident analysis using Query Builder and Michelangelo, extracting and interpreting data to support in-depth investigations.
  • Ticketing & SOP Development (Jira and Confluence ticket management): Created Jira tickets for issues uncovered during investigations and collaborated with relevant teams for resolution. Developed SOPs for new alert types, standardizing response procedures and improving operational efficiency.
  • Proactive Threat Hunting (Threat_hunt): Conducted pre-hunting and threat hunting based on application vulnerabilities, strengthening defenses by identifying potential threats before they materialize.
  • Incident Response & Resolution(IC_management): Actively participated in critical incident handling to develop mitigation skills. Ensured all tickets were resolved within SLA, balancing timely response with quality investigation.
  • Bug Bounty Management: Collaborated on bug bounty cases, working closely with teams to address and resolve vulnerabilities reported by external researchers.

Automation Project Work:

  • Playbook Development in SOAR (Splunk Phantom): Developed and optimized automated playbooks to streamline incident response workflows, reducing manual intervention and improving response times.
  • Automation Design: Designed playbooks to automate repetitive tasks such as alert triaging, phishing analysis, malware investigation, and data enrichment, using Phantom’s orchestration capabilities to gather and analyze information across multiple security tools.
    Error Handling & Debugging: Implemented robust error-handling mechanisms within playbooks to ensure smooth execution. Actively debugged issues in playbook logic, addressing integration challenges and workflow bottlenecks to maintain reliability..
    Improving SLA Compliance: Leveraged automation to acknowledge and investigate alerts within SLA limits, enhancing consistency in response times across high-volume cases.
    Testing & Continuous Improvement: Conducted thorough testing of playbooks in various scenarios, refining logic based on incident patterns and feedback to enhance performance and scalability.
    Cross-Tool Integrations: Integrated Phantom with various security tools (e.g., CrowdStrike, AWS GuardDuty, Gmail, and SIEM platforms) to build end-to-end automated workflows that increase incident detection and response accuracy.

Security Analyst

Cognizant
06.2017 - 04.2020
  • Monitored security alerts using IBM QRadar SIEM tool to ensure active threat detection and response.
  • Developed active channels, correlation rules, reports, and dashboards in IBM QRadar for real-time monitoring of alerts.
  • Identified and analyzed security threats and investigated reported anomalies.
  • Created detailed templates for newly detected alert signatures to facilitate client reporting.
  • Managed incident response within SLA requirements to maintain timely handling and resolution.
  • Fine-tuned SIEM event rules to minimize false positives and enhance alert accuracy.
  • Conducted daily health checks to maintain SIEM tool functionality.
  • Developed SOPs for new SOC procedures to streamline operations.
  • Prepared and delivered weekly and monthly reports as per client specifications.

Education

B.Tech., ECE -

Malla Reddy Institute of Engineering
Hyderabad, Telangana
05.2017

Intermediate -

Sri Chaitanya Junior College
Hyderabad, Telangana
05.2013

SSC -

SSM School
Hyderabad, Telangana
05.2011

Skills

  • SIEM (Security Information and Event Management) Tool: ELK Search Griffith, IBM Qradar, Splunk
  • EDR Tools: Crowd-strike, Open-Dns, Sentinel One, Azure Microsoft defender
  • Security tools: Teqtivity, Axonius, Ediscovery, Cloud Lock, G-suite toolbox, Joe sandbox, service now, Tableau, Cisco Umbrella, Jarvis, Opera, fleetdm application
  • Email Gateway tools: G-Suite, Proofpoint, Mimecast
  • QueryBuilder: Fetching data using Query Builder, Michelangelo (SQL)
  • Ticketing tools: Jira, ServiceNow
  • Skills on Linux-based commands
  • Knowledge on Windows, IOS, Linux

Certification

  • Certified Ethical Hacker (CEH), ECC5416230987
  • Ethical hacking and Information security certification, NIELIT/GKP/339/3897

Disclaimer

I hereby declare that all the details furnished above are true to the best of my knowledge. If given an opportunity, I would perform up to the best of your expectations.

Timeline

Cyber Security Technologist

Uber Technologies Inc.
04.2020 - Current

Security Analyst

Cognizant
06.2017 - 04.2020

B.Tech., ECE -

Malla Reddy Institute of Engineering

Intermediate -

Sri Chaitanya Junior College

SSC -

SSM School
Sathya Manikanta Gidugu