About
SOC Analyst with 2.5+ years of experience in a 24/7 enterprise Security Operations Center, including root-cause analysis of security incidents, SIEM detection rule tuning, and threat intelligence-driven investigation. Hands-on with Wazuh SIEM, Palo Alto Cortex XDR, Bitdefender, and Sophos EDR, with strong grounding in TCP/IP networking, Windows/Linux environments, and IDS/IPS, firewall, VPN, and antivirus technologies. Experienced developing and maintaining incident response playbooks and runbooks, and recommending process and detection enhancements within an ITIL-based Incident, Problem, and Change Management framework. Comfortable working rotational shifts in a high-volume, always-on SOC. CEH certified, with a consistent record of meeting SLA targets. Open to relocation and hybrid/onsite roles in Bengaluru.
Skills & Expertise (43)
Work Experience
SOC Analyst L1
Soffit Infrastructure Services Pvt. Ltd.
Dec 2023 - May 2026
Analyzed and triaged 80+ security alerts per week using Wazuh SIEM and Palo Alto Cortex XDR across insider threat, data exfiltration, and BEC scenarios, performing root-cause analysis and consistently meeting SLA targets over a 6-month period. Reviewed user behavior patterns and contextual indicators across SIEM and EDR platforms (Bitdefender, Sophos) to separate malicious activity from accidental data handling, tuning detection rules to reduce false positive alerts. Investigated data loss and email-based threats across Microsoft O365 (Exchange, SharePoint, OneDrive), performing email analysis and verdict categorization; helped identify 15+ BEC indicators that supported policy enforcement actions. Managed endpoint security operations across Palo Alto Cortex XDR, Bitdefender GravityZone, and Sophos Intercept X, handling alert correlation and endpoint isolation for high-severity incidents. Logged, tracked, and resolved incidents end-to-end using ManageEngine ServiceDesk, documenting investigation timelines and post-incident reports in line with ITIL Incident, Problem, and Change Management practices. Mapped detected threat behaviors to MITRE ATT&CK tactics and techniques, including Exfiltration (TA0010, T1048) and Phishing (T1566), to support structured investigations and detection tuning. Developed incident response playbooks and escalation runbooks adopted by the SOC team, and coordinated with IT, HR, and compliance to remediate active incidents and recommend DLP policy enhancements. Worked as part of a 24/7 SOC rotation, collaborating across shifts and with cross-functional teams to share findings and maintain continuous coverage.
Education
Bachelor of Commerce (B.Com) - Bharathiyar University
2018 - 2021 ยท India
Certifications
Certified Ethical Hacker (CEH)
EC-Council ยท 2022
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (43)
Click a skill to find developers with the same skill