Seeking a challenging role in Cyber Security, specializing in Security Monitoring and Analysis, incident response, Vulnerability assessment. Targeting Positions in Texas (US).
Overview
5
5
years of professional experience
1
1
Certification
Work History
Senior Digital Forensics Analyst
TIAA Global Capabilities
01.2021 - Current
Roles & Responsibilities: Skilled in various security technologies including Splunk(SIEM), QRadar (SIEM), Firewalls, IDS/IPS (Intrusion Detection System/Intrusion Prevention System), ESA (Email Security Appliance), Nexpose, Palo Alto, FireEye, Security Analytics, CrowdStrike, and Public Speaking
Knowledge on IAM suit with tools like Sail Point, Okta, CyberArk
Contributed to SOAR Tool - Tines onboarding, designing automation workflows with SOLO team members for improved incident response efficiency
Drill down investigation of security incident by analyzing logs from multiple logs sources which includes but not limited to Web Gateway, Firewalls, Mail Gateway, WAF, End Point Protection (Anti-Virus), IPS, IDS, Active Directory, Load Balancer, Operating System
Experience in SQL, LDAP, Kubernetes, Linux, CI/CD methodologies
Worked on Akamai Incidents related to network and DDos, Data Protection tool incidents (Imperva), Asset Management tool (TFS), security and data integrity tool like file changes (Tripwire), PAM alerts
Reporting outages and escalating issues to ensure timely resolution
Worked on various alerts provided by Threat Intelligence - Recorded Future, Phish Labs, Domain Tools
Collaborating with vulnerability and solo teams to fine-tune operations
Provided support, guidance, for variety of Cybersecurity initiatives/ alerts to team
Utilizing Apache, Python Scripts to identify intrusions and mitigating them
Creation of Security operation documents, control plan, run book, knowledge base and SOPs
Leading Information Security team at TIAA, highlighting proficiency in overseeing Security Monitoring and Operations with excellence
Acknowledged for comprehensive understanding of security principles, cyber threats, threat vectors, and managing security incidents effectively
Proficient in managing security incidents, resolving SIEM dashboard challenges, and ensuring security of client networks
Recent achievements include leading development of automated IP blocking dashboard, resulting in gold award in 2023
Verifying and resolving issues related to anomalous activity alerts from SIQ(Sail Point) and other user entity behavior (UEBA) platforms through escalations or exceptions
Integration experience in Security technologies with SIEM - CASB, PAM, EDR, UEBA and rules creation and analysis of alerts from various consoles
Developed, distributed and run anti-phishing campaigns and run data analytics and provided training for awareness
Worked as part of an Offshore Security Operations Center (SOC) team, responsible for monitoring SOC events, detecting & preventing intrusion attempts
Firsthand experience with Windows/Unix Security Logs, as well as logs from IDS/IPS, Host-based Intrusion Detection Systems (HIDS), Data Loss Prevention (DLP) systems, Cisco ASA, Next-Generation Firewalls, Anti-Virus/Malware solutions, and Active Directory Integration
Created use cases guides and workflows and given some automation ideas on procedures (experience of Confluence workspace), for this work I have received bronze award
Manage training and development activities for team.
Security Analyst
City Union Bank
08.2019 - 09.2020
Roles & Responsibilities: Conducted real-time monitoring, investigation, and analysis of security events
Reviewed and improved alert conditions to minimize false alarms
Experience with SAI 360 GRC platform
Conducting security gap analysis to assess compliance with laws, and industry standards
Result-oriented, which inspires to deliver high-quality work and follow deadlines and SLA
Collaborated with the SOC team to detect and prevent intrusion attempts
Documented security incidents and maintained ticket quality
Troubleshot SIEM dashboard issues to ensure seamless operations
Conducted regular security awareness training sessions for employees, resulting in the decrease in successful phishing attempts within the organization
Analyzing phishing emails and trend reports and taking remediation actions and coordinating with cyber awareness team to improve cyber awareness and user behavior
Presenting the monthly reports to respective stakeholder
Creation of Security operation documents, control plan, run book, knowledge base SOPs
Working on Security Advisory received from various sources and taking the action accordingly
Analyzing the use cases present on SIEM and sharing the fine-tuning suggestion to admin team
Analyzing the logs of various devices to detect anomalies, mis-configuration.
Education
MBA -
SSIM
Hyderabad
05.2019
Bachelor of Science - Computer Science
Avinash College Of Commerce
Hyderabad
05.2016
Skills
Crowd Strike (EDR)
Splunk
Symantec
Palo Alto (NGFW)
Dark Trace
Cisco
Azure AD
AWS
Linux
Vulnerability Assessment
Nexpose
Recorded Future
Tripwire
Microsoft Defender
Certification
CEH V10
Microsoft Azure Fundamentals AZ 900
TryHackMe (Multiple Certifications)
CompTIA Cysa +
Disclaimer
I hereby declare that the above information is accurate and true to the best of my knowledge.