Summary
Overview
Work History
Education
Skills
Websites
Certification
Languages
Training
Personal Information
Knowledgepreview
Timeline
Generic
VIVEK AHUJA

VIVEK AHUJA

Delhi NCR

Summary

With a robust background at TechMahindra Allyis Ltd., I excel in deploying state-of-the-art security technologies and enhancing incident response strategies. Expert in Alienvault SIEM and adept at fostering security awareness, my contributions have significantly improved client security posture, demonstrating a proactive approach and technical proficiency in a high-stakes environment.

Overview

12
12
years of professional experience
1
1
Certification

Work History

Senior Support Engineer

TechMahindra Allyis Ltd.
06.2022 - Current
  • Working on various state-of-the-art technologies like: Microsoft RiskiQ, Zendesk, Microsoft Threat Defender, Service now
  • Creating reports for generated incidents using Zendesk
  • Administering the Security Policy setting & configuration as per the security requirement in various segments
  • Ensuring that the escalated issues from network operations were handled as security engineering team member based on Onpriority and planning and executing any device deployment or upgrade
  • Responsible for the customer support experience with Microsoft
  • Own, troubleshoot and solve customer technical issues, using collaboration, troubleshooting best practices and transparency within and across teams (e.g
  • Swarming)
  • Identify cases that require escalation (either technically or strategically)
  • Drive technical collaboration and engagement outside of CSS (Product Engineering teams, Services, Support, Regions)

Senior SOC Analyst

Coforge Ltd.
Greater Noida
10.2020 - Current
  • Working on various state-of-the-art technologies like: Kibana, blusapphire, Service now, MacAfee Nitro SIEM, Cisco Amp, IBM Resilient Incident Response Platform, RSA SA And RSA Netwitness SIEM Platforms
  • RSA Archer and OS Ticket, Bugzilla for incident management; creating reports for generated incidents using RSA archer
  • Managing the SIEM Infrastructure by using RSA Netwitness and Alienvault SIEM; working on IDS/IPS LOG analysis, extraction and developing new rules, signatures and policies, Infrastructure/SOC Monitoring
  • Administering the Security Policy setting & configuration as per the security requirement in various segments
  • Ensuring that the escalated issues from network operations were handled as security engineering team member based on Onpriority and planning and executing any device deployment or upgrade
  • Maintaining a high level architectural view of the Network Security infrastructure and providing technical input in planning, estimating and design of project
  • Working on: Infoblox tool for DNS Addition and Blocking, Cisco Stealthwatch for Network Behaviour analysis and detection
  • Monitoring the: ESM, loggers, ArcMC and Symantec EDR
  • BEL assets and contributing in framing Incident Management & Response Policies and fine tune SOC processes and procedures
  • Uploading daily RSA Threat Intelligence Feed malicious emails, IP, domains and Ad-Hoc IOC requests from the client to ArcSight ESM under their respective lists
  • Creating standardized operating (SOPs) practices and procedures that ensured audit compliance and standard levels of agreement (SLA)
  • Contributing substantial work toward the efforts of establishing the Computer Security Incident Response Centre
  • Performing vulnerabilities assessments for the entire Enterprise and reported findings to management
  • Assessing and implementing Information and Communications Technology (ICT) / Information Security (IS) governance best practices, recommendations & Industry Information Security (IS) requirements
  • Coordinating with the global software delivery leadership in embedding operation risk framework within various cross-functional teams and global businesses; ensuring the adherence that the functions adopt the Control of Privilege Access Framework (CPA)
  • Facilitating internal and external audits; followed-up on audit issues responses, action plans & remediation
  • Liaising with the client to assess the requirement based in the business process analysis (As-Is, To-Be) & providing the optimum automation solutions

Senior SOC Analyst

Microland Ltd.
12.2019 - 09.2020
  • Worked on MacAfee Nitro SIEM, Cisco Amp, IBM Resilient Incident Response Platform, RSA SA And RSA Netwitness SIEM Platforms; worked on RSA Archer and OS Ticket, Bugzilla for incident management
  • Created reports for generated incidents using RSA archer; managed the SIEM Infrastructure by using RSA Netwitness and Alienvault SIEM
  • Worked on IDS/IPS LOG analysis, extracted and developed new rules, signatures and policies, Infrastructure/SOC Monitoring
  • Ensured that the escalated issues from network operations were managed as security engineering team member based on Onpriority and planning and executed any device deployment or upgrade
  • Maintained a high level architectural view of the Network Security Infrastructure and provided technical input in planning, estimating and design of project
  • Worked on: Infoblox tool for DNS Addition and Blocking, Cisco Stealthwatch for Network Behaviour analysis and detection, Prelude Open Source SIEM
  • Sent Stealthwatch Daily Analysis Reports to client and worked on ArcSight SIEM and fireeye apt

Project Engineer

Wipro Ltd.
Jaipur
01.2019 - 12.2019
  • Effectively Managed the SIEM Infrastructure by using RSA Netwitness and Alienvault SIEM; worked on IDS/IPS LOG analysis, extraction and developed new rules, signatures and policies, Infrastructure/SOC Monitoring
  • Managed security policy setting & configuration as per the security requirement in various segments
  • Ensured that the escalated issues from network operations as security engineering team member based on Onpriority and planned and executed any device deployment or upgrade
  • Maintained a high level architectural view of the Network Security infrastructure and provided technical input in planning, estimating and design of project
  • Created use cases using SIEM
  • Worked on: Infoblox Tool for DNS Addition and Blocking, Cisco Stealthwatch for Network Behaviour Analysis and Detection, Prelude Open Source SIEM
  • Sent Stealthwatch Daily Analysis Reports to client and worked on ArcSight SIEM (Under Testing now)

Senior Engg.

HCL Comnet Pvt. Ltd.
Mumbai
07.2016 - 01.2019
  • Company Overview: (Project IDBI Bank)
  • Monitored and analysed the security of critical systems (e.g., mail servers, databases, web servers) and changed highly sensitive computer security controls to ensure appropriate system administrative actions, investigate and report on noted irregularities to client, meetings with client on issues
  • Conducted the Log Analysis, Extraction using SIEM Tools and generating and sending reports to Client as per requirement
  • Managed the software and hardware upgrades, implemented and maintained procedures for backup and recovery of network servers and configuration files of other network devices
  • Conducted the SIEM Infrastructure by using RSA SA and Alienvault SIEM
  • Worked on IDS/IPS LOG analysis, extraction and developed new rules, signatures and policies, Infrastructure/SOC Monitoring
  • Involving in Security Policy setting & configuration as per the security requirement in various segments
  • Administered the Security Monitoring, Reporting, analysis to client using RSA SA and RSA Archer
  • Maintained a high level architectural view of the Network Security infrastructure and provided technical input in planning, estimating and design of project; created use cases using SIEM
  • (Project IDBI Bank)

SIEM/SOC Analyst

Control Case International Pvt. Ltd.
Mumbai
09.2014 - 06.2016

Officer

ICICI Bank Pvt. Ltd.
03.2013 - 10.2013

Education

PGDITISS - IT Infrastructure and System Security

CDAC
Bengaluru
01.2014

PGDBO - Banking Operations

University
01.2013

Bachelor of Technology - Computer Science

UTU
Dehradun
01.2012

Skills

  • Linux
  • Windows
  • MS Office
  • Openoffice
  • Alienvault SIEM
  • RSA SA
  • QRadar
  • MacAfee
  • ArcSight
  • Snort
  • ATP
  • MCM
  • Threat Intelligence
  • Networking Fundamentals
  • Networking Tools
  • Windows Active Directory
  • DNS
  • DHCP
  • IIS
  • Windows System Services
  • Administrative Tools
  • Nessus
  • OSWAP Top Ten Vulnerabilities
  • Ethical Hacking Fundamentals
  • SANS 25 Security Errors
  • TCPDUMP
  • SNORT
  • Basics of PKI
  • Oracle10g
  • MYSQL
  • AWS EC2
  • RSA Archer
  • OS Ticket
  • IBM Resilient Incident Response Platform
  • Cloud security
  • Threat intelligence
  • Log analysis
  • Security awareness training
  • Incident response
  • SIEM management
  • TCP and IP protocols

Certification

  • PG Diploma in Cyber Security from Gujarat Forensic SCIENCES University
  • CEH version 10 certified.
  • Certificate Course in Cloud Computing from CAD
  • Certificate of completion for MacAfee ESM v11.0 (Sales) training
  • Cyber Security Certificate from Pragyna Meter
  • Fortinet NSE Institute NSE1 Network Security Associate Certification.
  • Fortinet NSE Institute NSE2 Network Security Associate Certification.
  • Vskills cyber security certified analyst (pursuing)

Languages

Please Mention

Training

  • Cloud computing at CDAC Bangalore
  • Two days’ workshop on Grid Computing at CDAC Bangalore
  • Data Center Mgmt. at CDAC Knowledge Park Bangalore

Personal Information

Date of Birth: Please Mention

Knowledgepreview

  • SOC Analyst Security operations
  • Operation Risk Framework
  • Information Security & Compliance
  • Vulnerabilities Assessments
  • IT Processing Operations
  • Global Risk and Control Assessments
  • Stakeholder Engagement
  • Leadership and Team Management

Timeline

Senior Support Engineer

TechMahindra Allyis Ltd.
06.2022 - Current

Senior SOC Analyst

Coforge Ltd.
10.2020 - Current

Senior SOC Analyst

Microland Ltd.
12.2019 - 09.2020

Project Engineer

Wipro Ltd.
01.2019 - 12.2019

Senior Engg.

HCL Comnet Pvt. Ltd.
07.2016 - 01.2019

SIEM/SOC Analyst

Control Case International Pvt. Ltd.
09.2014 - 06.2016

Officer

ICICI Bank Pvt. Ltd.
03.2013 - 10.2013

PGDITISS - IT Infrastructure and System Security

CDAC

PGDBO - Banking Operations

University

Bachelor of Technology - Computer Science

UTU
VIVEK AHUJA