Experienced Network Security and Cybersecurity Engineer with a robust background in implementing and managing SIEM solutions such as Splunk and ArcSight. Proficient in configuring and administering firewalls including Palo Alto, Checkpoint, Cisco ASA, and Cisco Firepower. Skilled in deploying and managing EDR solutions such as CrowdStrike Falcon. Known for being an enthusiastic cybersecurity professional, passionate about identifying new threats, staying abreast of the latest trends, and employing innovative defensive security methods
Overview
18
18
years of professional experience
1
1
Certification
Work History
Systems Architect
Fujitsu Consulting India
01.2022 - Current
Configured and optimized Splunk SIEM for real-time threat detection, log collection, and correlation, ensuring effective incident response
Integrated new log sources, including firewalls, endpoint protection, and cloud services, into Splunk, enhancing its capabilities and scope
Analyzed logs to detect and investigate suspicious activities, identifying potential security threats and taking proactive measures to mitigate them
Created and optimized correlation rules, alarms, and use cases for attack detection, streamlining incident response and improving overall security posture
Automated response workflows using Splunk Smart Response actions, reducing incident resolution time and improving efficiency
Deployed and managed various security solutions, including Cisco ASA, Firepower, Palo Alto, Checkpoint, McAfee Web Gateway, and F5, ensuring secure connectivity and seamless communication
Configured firewall policies and implemented VPNs for secure connectivity, ensuring seamless communication and data transfer
Responded to incidents, participated in Priority 1 calls, and resolved critical issues promptly, demonstrating exceptional problem-solving skills and crisis management abilities
Executed change requests, performed OS patches and upgrades, and ensured adherence to change management policies, promoting efficiency, reliability, and continuous improvement
Managed device upgrades, evaluated compatibility, and ensured smooth installations, minimizing downtime and ensuring business continuity
Regularly upgraded software and firmware, including structured cabling systems, to maintain optimal system performance and ensure seamless operations
Documented and shared best practices and knowledge to promote continuous learning and improvement, fostering a culture of collaboration and knowledge sharing
Contributed to the development of security policies, procedures, and SOPs for SOC operations, ensuring compliance, efficiency, and effectiveness
Reviewed and enhanced SOC processes to adapt to evolving threats, promoting continuous improvement and staying ahead of emerging security risks
Contacted customers directly for high-priority incidents and assisted in attack mitigation, providing exceptional customer service and ensuring customer satisfaction
Onboarded data sources, including Windows, Linux, and Firewalls, ensuring seamless integration and optimal data visibility
Troubleshot devices not reporting to Splunk, resolving issues promptly and efficiently, and ensuring minimal downtime
Created dashboards and reports in Splunk, providing actionable insights and visualizations, and enabling data-driven decision making
Managed CrowdStrike EDR module, handled detections and triage, and performed searches, reports, and dashboards, ensuring effective threat detection and response
Utilized threat intelligence module and understood sandboxing reports, staying ahead of emerging threats and ensuring proactive security measures
Performed EDR host and user management, policy creation, and management, ensuring secure endpoint operations and minimizing risk
Installed/uninstalled agents on endpoints, maintaining endpoint visibility and control, and ensuring secure endpoint operations
Handled malware, performed dynamic analysis, incident response, and threat actor containment, demonstrating expertise in malware handling and incident response
Conducted threat hunting and applied methodologies such as Pyramid of Pain, identifying and mitigating potential threats, and staying ahead of emerging security risks
Understood Falcon administration and used skills to contain and remediate threats using RTR, ensuring swift and effective response
Provided comprehensive network infrastructure support for a multi-customer data centre, ensuring optimal performance, security, and reliability
Consultant
Atos Global IT Solutions and Services Pvt LTD
Chennai
11.2018 - 01.2022
Managed multiple Data Centres in North America, overseeing daily operations and resolving technical issues
Troubleshot complex problems related to Nexus Switches, Cisco ASA firewalls, IPSec VPN tunnels, MPLS routers, and other network devices
Configured and maintained Cisco ASA firewalls, making changes to ACL and NAT as required to ensure secure network operations
Built and troubleshooted IPSec VPN tunnels to connect Data Centres with various customers, ensuring seamless data transfer
Managed and troubleshot issues with Cisco Switches, Checkpoint Firewalls, Juniper SRX Firewalls, and Pulse Secure VPNs, resolving technical problems quickly
Coordinated patching and upgrade activities for Checkpoint, SRX, and Pulse Secure VPNs, ensuring timely updates and minimal downtime
Configured F5 VIPs based on application requirements and created A records in the GTM, ensuring high availability and scalability
Researched and resolved major incidents affecting the client's business, minimizing downtime and ensuring rapid recovery
Collaborated with other teams to plan and execute DR and DR simulation exercises, ensuring business continuity
Integrated and onboarded devices to SIEM tools like Splunk and ArcSight, enhancing threat detection and incident response capabilities
Designed and configured dashboards and correlation rules on ArcSight and Splunk, providing real-time insights and threat intelligence
Migrated configuration from Cisco ACE to F5 load balancers, improving application performance and availability
Technical Lead
Cognizant Technology Solutions
01.2013 - 11.2018
Managed LAN/WAN infrastructure for a retail store, ensuring business continuity and reliability
Configured and troubleshot network infrastructure, including switches, routers, firewalls, and load balancers, ensuring optimal network performance
Implemented access control and address translation rules on firewalls to regulate network traffic and maintain network security
Configured and troubleshot IPSEC VPN and SSL VPN for site-to-site and client-to-site users, ensuring secure remote access
Managed non-standard changes, including OS upgrades, rebuilds, and failovers, with proper change plans and R&I analysis, ensuring minimal downtime
Created and configured real servers, virtual servers, and port bindings in load balancers, optimizing application delivery
Implemented layer 2 port-based security for all hosts in the environment, ensuring secure network segmentation
Configured and troubleshot routing protocols, including OSPF, BGP, and EIGRP, in Cisco devices, ensuring optimal network routing
Managed VLAN and inter-VLAN security, and configured inter-VLAN routing on Layer-3 switches, ensuring secure network communication
Utilized Cisco Global Site Selectors for configuration and troubleshooting, streamlining network operations
Provided tier 2 technical support, assisting users with network problems and performing advanced troubleshooting and diagnostics, ensuring rapid issue resolution
Identified and resolved port failures and affected users and devices, minimizing network downtime
Coordinated with vendors for device replacements and worked with datacenter technicians to resolve hardware issues, ensuring prompt issue resolution
Monitored network performance regularly to improve performance and functionality, ensuring optimal network operations
Technical Support Executive
Sutherland Global Services
02.2011 - 10.2012
Utilized technical expertise to troubleshoot and resolve complex hardware issues for Symantec Antivirus clients, ensuring prompt resolution and minimizing downtime
Designed and implemented effective virus and spyware solutions to optimize system performance, ensuring seamless operation and enhanced user experience
Process Associate
Tata Consultancy Services BPO
07.2008 - 01.2011
Utilized market performance metrics to analyze market dynamics and identify areas for improvement at The Nielson, USA
Developed and implemented solutions to diagnose and resolve marketing and sales problems, uncovering growth opportunities and driving business results
Customer Support Executive
Reliance BPO LTD
04.2007 - 07.2008
Education
B. Com - Commerce
Acharya Nagarjuna University
Andhra Pradesh
12.2006
Board of Intermediate Education - 12th - Mathematics, Physics, Chemistry
G.A & K.A Junior College
03.2003
10th -
St. Joseph High School
Vijayawada, Andhra Pradesh
12.2000
Skills
Designed and implemented correlation rules, dashboards, threat detection, log analysis, and incident response using Splunk and ArcSight, resulting in enhanced security and incident response capabilities
Configured and administered firewalls from leading vendors, including Palo Alto, Checkpoint, Cisco ASA, and Cisco Firepower, ensuring robust network security and compliance
Deployed and managed CrowdStrike Falcon to provide endpoint security and threat detection, protecting against advanced threats and data breaches
Applied expertise in routing, switching, and network configuration to design and implement secure, efficient network architectures
Configured and managed F5 load balancers to optimize traffic distribution and network performance, ensuring high availability and scalability
remained proactive in identifying and mitigating potential security risks by staying up-to-date with emerging cybersecurity threats, trends, and defensive security methods
Utilized Microsoft Visio, Wireshark, and tcpdump to troubleshoot and resolve complex network issues, leveraging strong analytical skills and a methodical approach
Analyzed and responded to security incidents using tools such as Cisco Talos, MX Toolbox, and VirusTotal, ensuring timely and effective incident response
Collaborated with cross-functional teams to enhance the organizational security posture, leveraging strong communication, and interpersonal skills
committed to ongoing professional development, staying updated with the latest cybersecurity developments and certifications to maintain expertise and enhance career prospects