annapurna alluri
Cloud Security Engineer
About
Cloud Security Engineer with 5+ years of hands-on experience in Azure cloud security, Microsoft XDR deployment, SIEM/SOAR operations, threat intelligence, and SOC operations. Proven track record in designing and implementing enterprise-grade security solutions, conducting advanced threat hunting, managing vulnerability assessments, and leading phishing email investigations across hybrid cloud environments. Adept at leveraging Microsoft Sentinel, CrowdStrike Falcon, Splunk, and Microsoft Purview DLP to strengthen organizational security posture.
Skills & Expertise (36)
Work Experience
Cloud Security Engineer
Altimetrik
May 2021 - Present
Architected and deployed Microsoft XDR suite across 5,000+ endpoints integrating Microsoft Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps to achieve unified threat detection and response. Engineered and operationalized Azure Sentinel SIEM/SOAR platform with 50+ custom analytic rules, automated playbooks using Logic Apps, and custom KQL-based threat detection queries reducing mean time to detect (MTTD) by 40%. Led enterprise-wide Defender for Office 365 implementation configuring Safe Links, Safe Attachments, Anti-Phishing policies, and Zero-hour Auto Purge (ZAP) protecting 3,000+ mailboxes from advanced email threats. Conducted 500+ phishing email investigations using Microsoft Threat Explorer, analyzing email headers, URLs, and attachment payloads to identify phishing campaigns, business email compromise (BEC) attempts, and credential harvesting attacks. Managed Microsoft Entra ID (Azure AD) security configurations including Conditional Access Policies, Multi-Factor Authentication (MFA), Privileged Identity Management (PIM), and Identity Protection risk-based policies for 4,000+ user identities. Deployed and tuned CrowdStrike Falcon SIEM platform for real-time endpoint detection and response (EDR), configuring custom IOC feeds, behavioural analytics, and threat graph investigations across hybrid infrastructure. Administered Splunk SIEM environment building custom dashboards, correlation searches, and notable event frameworks to monitor security events across on-premises and cloud environments with 99.9% log ingestion uptime. Developed threat intelligence programs integrating MITRE ATT&CK framework, STIX/TAXII feeds, and open-source intelligence (OSINT) sources to proactively identify emerging threats and adversary tactics, techniques, and procedures (TTPs). Executed advanced threat hunting campaigns using KQL in Azure Sentinel and SPL in Splunk to detect lateral movement, privilege escalation, persistence mechanisms, and data exfiltration patterns across enterprise networks.
Education
Master of Technology (M.Tech) in Computer Science & Engineering - Swarnandhra Institute of Engineering & Technology
- 2015 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (36)
Click a skill to find developers with the same skill