Professional Experience
Rakuten India
Senior Security Analyst 1
06/2023 – Current
▪ Developed KQL queries and created storage accounts for analytical rules in Microsoft Sentinel, while also modifying logic
apps and creating watchlists to optimize threat detection.
▪ Resolved over 30% production-related issues by collaborating with engineering and quality assurance teams, serving as
the subject matter expert (SME) for production operations.
▪ Conducted root cause analysis (RCA) for major incidents by analyzing security logs from Sentinel and Crowd Strike, while
effectively addressing client escalations.
▪ Developed KQL Hunting Modules for analysts to identify security threats, leveraging logs from various security devices
including Firewalls, IDS/IPS, and Crowd Strike EDR to enhance threat detection.
▪ Developed and implemented threat hunting use cases using the TTPs addressing 20+ incident escalations from the Tier
2 group and performed root cause analysis and documentation for each Incident.
▪ Investigated intra alerts from CrowdStrike EDR incidents, including Falcon EDR and Falcon Mobile, which led to a 30%
faster incident resolution timeframe by improving clarity on threat visibility.
▪ Conducted anti-phishing operations and managed the release of over 500 emails daily using Trend Micro Cloud App
Security, reducing phishing incidents by effectively addressing email threats.
▪ Managed monthly reports on subsidiary security incidents, analyzing an average of 10 detailed attacks per session and
performing gap analysis to identify vulnerabilities.
▪ Implemented strategies that reduced false positive (FP) events by 20% in EDR systems and improved incident responses
for phishing logs in the production environment.
▪ Contributed to 3+ cybersecurity projects focused on non-CJ logs, facilitating communication between clients and the SOC
team to ensure effective incident response.
Security Analyst II
Atos
01/2023 – 06/2023
▪ Conducted in-depth threat hunting across diverse data models including Firewall, Proxy, IDS and Windows O365, Okta to
identify anomalies and potential security risks.
▪ Conducted manual investigations an over 200 log entries to validate threat models and identify irregularities-improving
anomaly detection capabilities.
▪ Delivered 50+ detailed anomaly reports through client SOAR platforms, resulting in a 30% faster incident response time
and guiding incident management decisions.
▪ Mapped hunting outcomes to MITRE ATT&CK techniques to improve detection coverage and gap analysis.
▪ Managed whitelisting of IP, user and hosts according to client policies, reducing false positives and streamlining alert
generation and Improvement in Processes.
▪ Collaborated with clients through regular calls to clarify findings, address concerns, and drive continuous team and
process improvements.
Security Analyst
Wipro
12/2016 – 01/2023
▪ Delivered 24×7 SOC production support with real-time log aggregation and monitoring using IBM QRadar SIEM and
executed endpoint remediation and user awareness initiatives.
▪ Managed Ll triage and incident management for over 100 incidents monthly in ServiceNow, tuned correlation rules,
and implemented security policies by responding to user violation alerts.
▪ Engineered and optimized CJ/non-CJ detection rules and reference sets to enhance SIEM alert fidelity and threat
intelligence.
▪ Optimized security protocols to reduce false positives by 25% in the Incident Generation from analytical rules.
▪ Developed and maintained 10+ SOPs for security event handling and incident response, standardizing workflows and
improving incident response times.
▪ Served as escalation point and on call member, managing over 50 incident reports weekly and facilitating
communications through SharePoint and Microsoft Teams to streamline incident resolution.
Education
2021 – 2023
M.Tech in System Engineering, Bits Pilani University
2017 – 2021
B.Tech in System Engineering, Bits Pilani University
interests
homelabs
reverse engineering
windows internal
IDS – Signature generation
containers + Clusters
networks
Hiking
running
Photography