About
No bio added yet
Skills & Expertise (37)
Work Experience
Manager – Cyber Threat Hunting — Information Security Group
ICICI Bank
Jun 2023 - Present
Conducted proactive hypothesis driven and retroactive hunting across endpoint, identity, cloud and network telemetry to identify Indicators of Compromise (IOCs) and Indicators of Attack (IOAs) using behavioral TTP analysis and multi-source telemetry correlation. Developed and enhanced ATT&CK-aligned threat hunting methodologies by transitioning from IOC-focused investigations to behavior-driven hunting approaches across enterprise environments. Performed incident investigations and root cause analysis using SIEM and EDR platforms, supporting containment validation and response coordination with SOC and engineering teams. Authored and optimized behavioral detections using XQL, SQL, and AQL in SIEM and EDR/XDR/XSIAM to improve visibility into lateral movement, credential abuse, persistence, defense evasion, and anomalous activity. Conducted purple team exercises simulating real-world attack scenarios across Windows and Linux environments to validate detection coverage and identify monitoring gaps. Researched malware campaigns, adversary behaviors, and emerging TTPs using Any.Run, Hybrid Analysis sandbox, VirusTotal, OSINT, Recorded Future, and threat intelligence platforms. Enriched investigations with IOC analysis and built dashboards to detect intrusion attempts by tcp/ip, firewall, IDS/IPS telemetry correlation. Collaborate with SOC, threat intelligence, and engineering teams to improve detection logic, close telemetry visibility gaps, strengthen incident response workflows and reducing MTTD(Mean time to detect). Prepared and presented actionable threat hunting reports, incident briefings, intelligence summaries, and Threat Landscape for both technical and management stakeholders. Contributed to ISMS ISO 27001 audit readiness, evidence collection, security control mapping, and gap assessments. Identified and responsibly disclosed vulnerabilities/security gaps in enterprise tooling, including a plaintext credential exposure issue involving Microsoft tooling and multiple product gaps in Palo Alto Cortex XDR, followed by patch issued.
Education
Bachelor of Technology - National Institute of Technology, Allahabad
2019 - 2023 · Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Need Sponsorship
Relocation
Depends on Offer
Skills (37)
Click a skill to find developers with the same skill