Summary
Overview
Work History
Skills
Certification
Timeline
Generic
Assan Saparkhanov

Assan Saparkhanov

Walnut Creek,US

Summary

Cloud Security Engineer with the Cloud and AI Security Engineer Associate (SC-500) certification and 6+ years of experience progressing from SOC analyst to cloud security. Specializes in Microsoft Azure, Microsoft 365, and hybrid environments. Experienced in securing identities, endpoints, and data with Entra ID, Conditional Access, PIM, Defender XDR, Intune, and Purview DLP, and in detecting threats with Microsoft Sentinel and KQL. Applies Zero Trust and least privilege principles across Azure and AWS

Overview

1
1
Certification
6
6
years of professional experience

Work History

Cloud Security Engineer

Citi Bank
San Francisco
01.2023 - Current
  • Architected and secured hybrid Azure and Microsoft 365 environments spanning on-premises Active Directory and cloud workloads, applying Zero Trust principles to protect organizational resources and data.
  • Administered Microsoft Entra ID (Azure AD), designing Conditional Access policies and Identity Protection risk policies. Monitored and investigated risky sign-ins and risky users to prevent account compromise.
  • Enforced least privilege through Azure RBAC and Privileged Identity Management (PIM) with just-in-time, approval-based elevation, strengthening governance across Azure resources.
  • Managed AWS IAM users, roles, and policies, applying least-privilege access and MFA enforcement to support a secure multi-cloud environment.
  • Implemented and managed Microsoft Purview Data Loss Prevention (DLP) policies to detect and prevent the exposure and exfiltration of sensitive data across Microsoft 365.
  • Configured and managed Microsoft Defender for Office 365 Safe Links and Safe Attachments policies to protect users from malicious URLs, phishing, and weaponized email attachments.
  • Led endpoint security initiatives with Microsoft Intune, managing device enrollment, configuration profiles, and device compliance policies integrated with Conditional Access.
  • Partnered with system administrators and cloud engineers to onboard and secure endpoints with Microsoft Defender for Endpoint (MDE). Deployed Antivirus, Firewall, Tamer Protection, and Attack Surface Reduction (ASR) rules to minimize the attack surface.
  • Configured and integrated Microsoft Defender for Identity (MDI) to detect abnormal user behavior, privilege escalation, and lateral movement across the hybrid identity environment.
  • Developed and deployed custom Microsoft Sentinel analytics rules using KQL to improve threat detection coverage and monitoring.
  • Automated security operations and Azure resource management with PowerShell scripting, improving efficiency and reducing manual effort.
  • Monitored, investigated, and responded to security incidents in collaboration with the SOC team, ensuring timely containment and remediation of threats.
  • Improved Azure and Microsoft 365 security posture by collaborating with cloud engineers and IT administrators to implement security best practices and remediate identified gaps.

Security Engineer

Verizon
San Francisco, CA
11.2021 - 12.2022
  • Monitored, triaged, and investigated security alerts across endpoints, identities, email, and cloud workloads, escalating confirmed threats and supporting incident response through containment and recovery.
  • Conducted vulnerability management using Microsoft Defender Vulnerability Management, identifying, prioritizing, and tracking remediation of vulnerabilities and misconfigurations with IT and infrastructure teams.
  • Assessed Azure resources with Microsoft Defender for Cloud, remediating security recommendations and aligning configurations with CIS Benchmarks and the Microsoft Cloud Security Benchmark (MCSB).
  • Applied Azure Policy to enforce security standards and prevent non-compliant resource deployments, supporting consistent governance across subscriptions.
  • Supported identity and access management in Active Directory and Entra ID, including user access reviews, group management, and the rollout of Multi-Factor Authentication (MFA).
  • Investigated phishing and suspicious emails reported by users, analyzing headers, URLs, and attachments, and removing malicious messages to prevent user compromise.
  • Hardened Windows servers and endpoints using Group Policy (GPO) and security baselines, and supported patch management to reduce exposure to known vulnerabilities.
  • Queried logs in Microsoft Sentinel using KQL to hunt for suspicious activity and support investigations, building the foundation for detection engineering.
  • Created and maintained security documentation, incident response playbooks, and standard operating procedures (SOPs) to improve consistency and knowledge sharing across the team.
  • Supported security awareness efforts by helping run phishing simulations and educating users on security best practices.

Security Analyst

Verizon
San Francisco
09.2020 - 10.2021
  • Monitored and triaged security alerts in a Security Operations Center (SOC) using Microsoft Sentinel and Microsoft Defender XDR, distinguishing true positives from false positives and escalating confirmed incidents to senior analysts.
  • Performed initial investigation of alerts involving suspicious sign-ins, malware detections, and anomalous user activity, documenting findings and timelines in the ticketing system following established incident response procedures.
  • Analyzed user-reported phishing emails, reviewing email headers, sender reputation, URLs, and attachments, and supported removal of malicious messages from user mailboxes.
  • Reviewed Entra ID sign-in logs and audit logs to identify impossible travel, unfamiliar locations, and failed MFA attempts, and supported password resets and account lockouts for compromised users.
  • Used threat intelligence sources such as VirusTotal, AbuseIPDB, and URLScan.io to enrich alerts and assess indicators of compromise (IOCs), including IP addresses, domains, and file hashes.
  • Ran basic KQL queries in Microsoft Sentinel to search logs, validate alerts, and gather evidence for investigations.
  • Followed SOC playbooks and escalation procedures, and contributed to improving them by documenting recurring alert patterns and recommending tuning for noisy detections.
  • Mapped observed attacker behavior to the MITRE ATT&CK framework to support accurate alert classification and reporting.
  • Collaborated with IT support and senior security staff to contain threats, including isolating devices in Microsoft Defender for Endpoint and disabling compromised accounts.
  • Prepared shift handover notes and incident summaries for senior analysts and management, keeping communication clear and consistent across the team.

Skills

  • Microsoft Azure Security
  • Microsoft Entra ID (Azure AD)
  • Conditional Access and Identity Protection
  • Privileged Identity Management (PIM) and Azure RBAC Microsoft Sentinel (SIEM) and KQL
  • Microsoft Defender XDR (Endpoint, Identity, Office 365)
  • Microsoft Defender for Cloud
  • Azure Network Security (NSGs, Azure Firewall)
  • Azure Key Vault
  • Microsoft Intune
  • Microsoft Purview Data Loss Prevention (DLP) AWS IAM
  • Incident Response and Threat Detection
  • Hybrid Cloud Security (On-Premises and Cloud)
  • Zero Trust Architecture and PowerShell Automation

Certification

2026 – 2027 Microsoft Certified: Cloud and AI Security Engineer. Credential ID: 2B8oE17B4B21EF06

Timeline

Cloud Security Engineer

Citi Bank
01.2023 - Current

Security Engineer

Verizon
11.2021 - 12.2022

Security Analyst

Verizon
09.2020 - 10.2021
Assan Saparkhanov