akula ajay
Security Analyst
About
Experienced Security Analyst with 4+ Years of expertise in incident response, digital forensics & malware analysis. Adept at leading and managing investigations, identifying, and mitigating security threats, and fortifying systems against cyber-attacks. Skilled in collaborating with executive leadership to develop and implement robust security strategies that enhance organizational resilience.
Skills & Expertise (45)
Work Experience
Security Analyst
Wipro
Mar 2023 - May 2026
Good knowledge of the MITRE ATT&CK framework, the diamond model, and other cyber threat kill chains. Experience in Azure Sentinel, creating playbooks using Logic Apps, and the creation of automation rules to auto-close incidents. Experienced in investigating phishing, spam, malware, and Business Email Compromise (BEC) attacks using Proofpoint and coordinating remediation activities. Experienced in creating the use cases and log analytics rules and custom detection rules using the KQL and SPL languages in Sentinel and Splunk. Working experience in a SOC environment with hands-on experience using the SIEM Splunk tool, which includes log analysis, fine-tuning existing correlation rules to reduce false positives, and responding to incidents. Good knowledge and working experience in central logging, log management, and Splunk SIEM architecture. Analyze, contain, and eradicate malicious activity detected from real-time alerts and manual threat hunts. Performed alert triage and fine-tuned detection rules to reduce false positives and improve the quality of security alerts. Experienced in examining suspicious emails for malicious content and providing recommendations on remediation actions using Proofpoint. Good understanding of Azure Active Directory, Azure MFA, and conditional access. In-depth knowledge of web application and network attacks, and the logs generated by these attacks, to properly investigate security incidents. Performed phishing investigations by analyzing message headers, SPF/DKIM/DMARC results, sender reputation, and Indicators of Compromise (IOCs) to support incident response activities. Managed enterprise email security using Proofpoint Email Security Gateway by monitoring, analyzing, and remediating phishing emails, spam, malicious attachments, malicious URLs, and Business Email Compromise (BEC) threats in enterprise environments. Conducted proactive threat hunting using Microsoft Defender XDR and KQL to identify suspicious activities and validate security alerts.
Security Analyst
Capgemini
Jan 2022 - Mar 2023
Experience in Data Analytics, Advanced Data Analytics, Visualization, Advanced Visualization, Dashboard Customization, and Advanced Dashboard Customization in Splunk. Monitor, respond to, and analyze trends in workstations, servers, and security-related events. Perform daily, weekly, and monthly scheduled tasks for Defender ATP. Experienced in writing correlation rules with respect to KQL and SPL languages. Experience in configuring and tuning ASR policies in the Microsoft 365 Defender portal. A good understanding of creating the threat and vulnerability management report regarding exposed devices, the impact of the application, and the overall security posture. Investigated phishing emails, malicious URLs, domains, and IP addresses using Microsoft Defender and open-source intelligence tools, recommending appropriate containment actions. Strong experience in managing Endpoint Agents over Windows and Linux operating systems, Active Directory integrations, and Windows Event Logs. Experience in adding and deploying client onboarding packages and configuration files; Configuration Manager can monitor deployment status, and Microsoft Defender ATP agent health. Experience in providing end-to-end support to enterprise counterparts, identifying the root cause of sophisticated enterprise initiatives, and implementing endpoint security solutions such as Microsoft Defender ATP. Managed incident response activities, including investigation and reporting of security breaches. Managed firewalls, antivirus systems, and other security tools to safeguard information assets. Managed Microsoft Defender policies, endpoint onboarding, agent health monitoring, and endpoint security configurations using Microsoft Intune. Performed root cause analysis for the incidents reported at the security operations center. Analysis of phishing emails reported by users to identify the type of attack, and take immediate remediation. Proficiency in using various security tools and technologies, such as firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), antivirus software, proxies, SIEM (Security Information and Event Management), and threat intelligence platforms. My role is analyzing external threats such as phishing and spam emails, and logging them in the SIEM tool. Analyze the nature and source of security threats, understanding their tactics, techniques, and procedures (TTPs).
Education
MCA - Dr.B.V.Raju Institute of Computer Education
- 2021 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Relocation
Open to Relocation
Skills (45)
Click a skill to find developers with the same skill