Ajay Gandikota
Security Analyst
About
Security Analyst with 2 years of experience in Security Operations Center (SOC) operations, Incident Response, Threat Hunting, and Endpoint Security, specializing in Microsoft Sentinel, Microsoft Defender XDR, Microsoft Intune, and Identity & Access Management. Proven expertise in developing and fine-tuning detection use cases recommendation, creating Sentinel analytic rules and automated playbooks, managing EDR lifecycle, conducting ransomware and phishing investigations, DLP, vulnerability management. Skilled in KQL, SPL, security reporting, and collaborating with cross-functional teams to enhance threat detection, automate response workflows, and improve the organization's overall.
Skills & Expertise (71)
Work Experience
Security Analyst
TCS
Jun 2024 - Present
Monitored and managed security incidents across enterprise environments using SIEM, EDR, email security, and cloud security platforms. Performed end-to-end Incident Response activities, including detection, investigation, containment, eradication, recovery, and post-incident analysis. Conducted proactive threat hunting using behavioral analytics, MITRE ATT&CK techniques, and Indicators of Compromise (IOCs). Investigated advanced ransomware, malware, phishing, credential theft, and insider threat incidents. Performed IOC analysis and blocked malicious IP addresses, domains, URLs, file hashes, and email senders across multiple security platforms. Created, modified, and fine-tuned Microsoft Sentinel Analytic Rules to improve detection accuracy and reduce false positives. Developed and maintained Microsoft Sentinel Playbooks using Logic Apps to automate incident response activities. Optimized SIEM detection use cases by reducing alert noise and improving threat visibility. Created custom KQL queries for advanced threat hunting, log analysis, dashboards, and investigations. Utilized SPL queries to investigate security events, identify anomalies, and develop custom detection logic. Monitored endpoint security using Microsoft Defender for Endpoint and ensured endpoint protection compliance. Managed EDR onboarding and offboarding of Windows, Linux, and macOS devices across enterprise environments. Performed regular endpoint health checks and compliance validation to ensure security policy adherence. Supported EDR migration activities, including planning, deployment, validation, and post-migration health verification. Investigated ransomware detections and coordinated rapid containment to minimize business impact. Performed malware analysis by reviewing process trees, command-line activities, persistence mechanisms, and endpoint telemetry.
Education
B.SC: COMPUTERS - Andhra University
- 2024 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (71)
Click a skill to find developers with the same skill