Back to Developers
Mohammad Shaif Shaif

Mohammad Shaif Shaif

Cyber Security Technical Specialist

Vasundhara, Ghaziabad, Uttar Pradesh, India
80
Profile Score

About

Cybersecurity Professional with 8+ years of experience in Security Operations (SOC), SIEM Monitoring, Incident Response, Threat Intelligence, and Malware Analysis. Skilled in handling high-severity alerts, phishing investigations, threat hunting, and endpoint triage. Experienced in tools like Splunk, QRadar, Azure Sentinel, Defender, Crowdstrike, and Mandiant. Strong in documentation, investigation procedures, and reporting.

Skills & Expertise (26)

SIEM Monitoring & Incident Response Expert
9.1/10
7
Years Exp
24x7 SOC Operations & Shift Handover Expert
8.9/10
7
Years Exp
Malware & Phishing Analysis Advanced
8.8/10
6
Years Exp
Splunk Expert
8.8/10
7
Years Exp
Incident Lifecycle Management & RCA Advanced
8.7/10
5
Years Exp
Cloud Security Advanced
8.7/10
5
Years Exp
Cyber Kill Chain & MITRE ATT&CK Framework Advanced
8.6/10
6
Years Exp
CrowdStrike Advanced
8.6/10
5
Years Exp
Threat Intelligence & IOC Correlation Advanced
8.5/10
5
Years Exp
QRadar Advanced
8.5/10
6
Years Exp
Endpoint Detection & Response (EDR) Advanced
8.5/10
5
Years Exp
Azure Sentinel Advanced
8.4/10
5
Years Exp
Network Forensics Advanced
8.4/10
5
Years Exp
Mandiant Advanced
8.3/10
5
Years Exp
Email Security Advanced
8.3/10
6
Years Exp
Custom Use Case Development & Alert Fine-tuning Advanced
8.3/10
5
Years Exp
Firewall Analysis Advanced
8.2/10
6
Years Exp
Defender Advanced
8.2/10
5
Years Exp
Vulnerability Management & Patch Coordination Advanced
8.1/10
5
Years Exp
Compliance & Audit Support Advanced
8.0/10
5
Years Exp
ServiceNow Advanced
7.9/10
5
Years Exp
BMC Remedy Advanced
7.5/10
5
Years Exp
TCP/IP Advanced
7.5/10
5
Years Exp
OTRS Intermediate
7.0/10
4
Years Exp
Security Documentation SOPs & Reporting

Work Experience

SOC Consultant (L2 Analyst)

Ernst & Young (via Spectrum Talent)

Oct 2020 - Dec 2021

Operated as an L2 Analyst in a 24x7 global SOC, responsible for triaging and escalating critical incidents. Investigated malware alerts, brute force attacks, unauthorized access, and suspicious user activity. Performed log analysis and event correlation across endpoints, firewalls, and cloud environments. Created incident tickets with detailed evidence, root cause analysis, and containment steps. Collaborated with internal teams and external vendors to ensure timely resolution and reporting.

Security Analyst

Nthrive Solutions Pvt. Ltd

May 2019 - Oct 2020

Worked on Splunk dashboards for real-time monitoring, log correlation, and security reporting. Investigated alerts related to malware, failed logins, and unauthorized access within healthcare systems. Managed daily security events from endpoints, email gateways, and firewalls. Collaborated with incident response teams to contain and escalate verified threats. Ensured compliance with SLA, internal security policies, and HIPAA requirements.

SOC Consultant

Deloitte Touche Tohmatsu India LLP

Jan 2022 - Apr 2023

Monitored, analyzed, and triaged security events in a 24x7 SOC environment using QRadar and Splunk. Investigated phishing campaigns, malware alerts, brute-force attempts, and privilege misuse. Conducted deep-dive log analysis and correlated events from endpoint, network, and email telemetry. Performed RCA on major incidents and contributed to security improvement actions. Tuned SIEM rules and alerts to align with real-world threats and reduce false positives by over 30%. Drafted incident reports, weekly summaries, and case documentation for client-facing dashboards. Collaborated with internal GRC, IAM, and threat intel teams for context enrichment and escalation decisions. Ensured timely escalation, SLA adherence, and complete ticket lifecycle management in ServiceNow.

SOC Analyst

Pacific KPO Pvt. Ltd

Dec 2017 - Apr 2019

Monitored security alerts and events using SIEM tools (QRadar & Splunk). Assisted in triaging phishing and malware incidents. Participated in daily shift handovers, documenting incident progress. Collaborated with L2 analysts for deep-dive investigations. Maintained IOC lists and supported log source onboarding.

SOC Analyst

Ienerziner Pvt. Ltd

Dec 2016 - Dec 2017

Supported SOC team in basic event analysis and log review. Helped prepare shift summary reports and incident response checklists. Learned cybersecurity fundamentals, TCP/IP basics, and common threat vectors. Gained exposure to Splunk, Windows event logs, and MITRE ATT&CK framework.

Technical Specialist

HCL Technologies

Apr 2023 - Present

Functioning as a SOC L3 Analyst in a global 24x7 environment, leading critical incident investigations and escalations. Mentoring L1/L2 SOC analysts, providing guidance, case reviews, and technical coaching during shifts and handovers. Conducting deep-dive analysis on phishing attacks, malware outbreaks, and endpoint security incidents across hybrid infrastructure (on-prem/cloud). Leading incident response for high-severity threats including credential compromise, C2 activity, and lateral movement. Documenting lessons learned from major incidents and updating SOC SOPs, IR workflows, and escalation paths. Preparing executive-level incident summaries, trend analysis reports, and SOC performance metrics on a weekly basis. Participating in change management calls and security control reviews with client stakeholders.

Education

B.Com - Delhi University

- 2015 · Afghanistan

12th - Kendriya Vidyalaya, Mumbai (CBSE)

- · Afghanistan

10th - Kendriya Vidyalaya, AFS Hindan (CBSE)

- · Afghanistan

Interested in this developer?

Profile Score Breakdown

📷 Photo 10/10
📄 Resume 10/10
💼 Job Title 10/10
✍️ Bio 10/10
🛠️ Skills 20/20
🎓 Education 10/10
⏱️ Experience 5/15
💰 Rate 0/5
🏆 Certs 0/5
Verified 5/5
Total Score 80/100

Profile Overview

Member sinceFeb 2026

Skills (26)

SIEM Monitoring & Incident Response 24x7 SOC Operations & Shift Handover Malware & Phishing Analysis Splunk Incident Lifecycle Management & RCA Cloud Security Cyber Kill Chain & MITRE ATT&CK Framework CrowdStrike Threat Intelligence & IOC Correlation QRadar +16 more