SOC Analyst with 12+ months of hands-on experience across two security operations roles, specializing in alert triage, SIEM detection engineering, and incident response. Proficient in Microsoft Sentinel (KQL), Splunk, and Sumo Logic for threat detection; Tines and Shuffle for SOAR automation; and Lima Charlie and Velociraptor for endpoint investigation.
Contributed to MITRE ATT & CK-mapped detection rules and SOC playbooks covering phishing, lateral movement, and credential abuse. Cloud security exposure spans AWS (Cloud Trail, Guard Duty) and Azure (Monitor, Entra ID, Defender for Cloud).
Quantix IT Ltd
UK (Remote)
Monitored and triaged security alerts in Sumo Logic SIEM across multi-client enterprise environments; managed full incident lifecycle from detection through closure via Zendesk ticketing. Assisted in configuring SOAR-based automation for alert enrichment, IOC correlation, and escalation routing, contributing to reduced manual analyst overhead.
Authored and maintained SOC runbook documentation, standardizing investigation workflows and detection coverage guidance across the analyst team.
Gardiyan System Security Technologies
Ankara, Türkiye (Remote)
Triaged alerts across endpoint, identity, and network telemetry including Windows Event Logs and Sysmon; contributed to tuning 12+ Microsoft Sentinel detection rules, reducing false-positive volume through root-cause analysis. Contributed to 10+ SOC playbooks covering phishing, DNS tunneling, and DoS scenarios, each mapped to specific MITRE ATT & CK tactics and techniques.
Automated alert triage workflows in Tines and Shuffle using Python and Bash scripts, eliminating approximately 10 hours/week of repetitive manual enrichment effort. Conducted adversary simulations using Atomic Red Team and Caldera (alongside custom scripts) targeting credential access (T 1003), command execution (T 1059), valid accounts (T 1078), and WMI (T 1047); findings informed detection rule refinements.
CyberSRC Consultancy Pvt. Ltd.
Noida, India (Remote)
Analyzed Wazuh alerts and event telemetry to surface anomalies, validate detection rule configurations, and support ongoing security monitoring operations. Produced client-facing security documentation including remediation guidance, findings summaries, and audit-ready evidence packages.
Bachelor of Technology (B.Tech.) in Cyber Security
Architected a modular SOC detection platform on Wazuh + Elasticsearch to monitor Kubernetes workloads; integrated a Python/Streamlit UEBA engine for insider threat and account takeover detection. Built an automated SOAR pipeline integrating The Hive, Cortex, MISP, and OpenCTI with custom enrichment workflows that eliminate repetitive IOC lookups from manual triage.
Stack: Wazuh, Elasticsearch, The Hive, Cortex, MISP, OpenCTI, Kubernetes, Prometheus, Grafana, Python
Deployed an enterprise-grade Zero Trust environment using Pomerium and Keycloak for identity-aware access control, with Apache Ni Fi and Presidio managing automated PII discovery and DLP enforcement. Hardened containerized workloads on K 3 s using Trivy and Falco; unified Suricata, Wazuh, and Cloud Custodian logs into an ELK Stack XDR pipeline for centralized threat visibility.
Stack: Keycloak, Pomerium, Suricata, Falco, Trivy, ELK Stack, K 3 s, Python
IIT Madras
$750 awarded across competitions