Back to Developers
Kiran Kumar Ganugula

Kiran Kumar Ganugula

Cyber Security Analyst

Chennai 4+ yrs exp 89 ยท Excellent

About

Cyber Security Analyst with 4.5+ years of experience across Security Operations Center (SOC) environments, specializing in threat detection, incident response, SIEM engineering, and SOAR-driven security automation. Hands-on expertise administering and tuning Azure Sentinel, IBM QRadar, and Splunk, combined with playbook development on Splunk Phantom, Palo Alto Cortex XSOAR, FortiSOAR, D3, and Titan SOAR to automate detection-to-response workflows. Skilled in mapping adversary behavior to the MITRE ATT&CK framework and Cyber Kill Chain, applying CIA Triad principles to risk-based decision making, and securing hybrid workloads across AWS and Microsoft Azure cloud environments. Proven track record in false-positive reduction and detection tuning, digital forensics and evidence handling, DLP policy monitoring, and cross-functional collaboration with IT, cloud, and vulnerability management teams to strengthen enterprise security posture.

Skills & Expertise (40)

Azure Sentinel Advanced
8.4/10
2
Years Exp
IBM QRadar Advanced
8.0/10
2
Years Exp
Splunk Advanced
8.0/10
2
Years Exp
KQL Advanced
8.0/10
2
Years Exp
Python Intermediate
7.6/10
2
Years Exp
PowerShell Intermediate
7.6/10
2
Years Exp
AWS Intermediate
7.4/10
2
Years Exp
Microsoft Azure Intermediate
7.4/10
2
Years Exp
MITRE ATT&CK Intermediate
7.0/10
2
Years Exp
Cyber Kill Chain Intermediate
7.0/10
2
Years Exp
TrendMicro DLP McAfee ProofPoint Symantec Mimecast Cofense IronPort O365 Palo Alto Zscaler Fortinet IDS IPS D3 Qualys Nessus Jira ServiceNow Splunk Phantom Palo Alto Cortex XSOAR LINUX SPL FortiSOAR Microsoft Defender ATP Falcon CrowdStrike Cybereason Carbon Black SentinelOne CIA Triad

Work Experience

Security Analyst

TCS

Jul 2022 - Present

Conducted critical incident analysis using SIEM tools such as Azure Sentinel, IBM QRadar and Splunk to identify and mitigate security threats promptly. Collaborated with L1 analysts to triage alerts, ensuring accurate assessment and escalation of potential security incidents. Utilized EDR solutions including SentinelOne, Carbon Black, Cybereason, Falcon CrowdStrike, and Microsoft Defender ATP for comprehensive endpoint threat detection and response. Own end-to-end triage and investigation of high-severity alerts across Azure Sentinel and IBM QRadar, correlating events across identity, endpoint, and network layers. Design and maintain automated response playbooks in Splunk Phantom and Cortex XSOAR, cutting mean-time-to-respond (MTTR) on repeatable incident types. Map confirmed incidents to MITRE ATT&CK techniques and the Cyber Kill Chain to identify coverage gaps and prioritize new detection use cases. Author complex KQL queries in Sentinel to hunt for credential abuse, lateral movement, and living-off-the-land activity across enterprise logs. Drive SIEM rule tuning and false-positive reduction initiatives, improving signal-to-noise ratio and reducing analyst alert fatigue. Investigate incidents involving phishing, ransomware precursors, and brute-force attempts, applying digital forensics techniques to preserve evidence and reconstruct attack timelines. Monitor and enforce DLP policies and endpoint controls via Microsoft Defender for Endpoint to prevent unauthorized data exfiltration.

Associate Analyst

TCS

Dec 2021 - Jul 2022

Support cloud security operations across AWS and Azure, reviewing IAM configurations, security groups, and cloud-native alerts for misconfigurations. Apply CIA Triad principles to risk-rank findings and guide remediation priorities in coordination with infrastructure and cloud teams. Build FortiSOAR/D3/Titan automation connectors to enrich alerts with threat intel from VirusTotal, AbuseIPDB, and AlienVault OTX prior to analyst review. Mentor associate analysts on triage methodology and document runbooks used for SOC onboarding and escalation procedures. Developed and optimized advanced KQL queries in Azure Sentinel to detect sophisticated attack patterns, improving threat detection coverage and reducing mean time to detect (MTTD). Applied strong Linux fundamentals to analyze system logs (syslog, auth.log, secure logs) and investigate suspicious activities across Linux-based servers. Utilized KQL (Azure Sentinel) and SPL (Splunk Processing Language) to perform advanced threat hunting and log analysis. Created and maintained documentation for SOAR playbooks, integrations, and incident handling processes to support knowledge sharing and compliance. Implemented automated incident response workflows using SOAR platforms including Splunk Phantom, FortiSOAR, D3 Security, Cortex XSOAR, and Titan to improve response efficiency. Leveraged Microsoft Defender suite (Defender for Endpoint, Defender for Identity, Defender for Cloud Apps) for advanced threat detection, automated investigation, and response. Performed false positive tuning and alert optimization by refining SIEM correlation rules, reducing alert fatigue and improving SOC efficiency. Conducted proactive endpoint threat hunting using behavioral indicators and EDR query capabilities. Monitored and secured cloud environments in AWS and Microsoft Azure, ensuring compliance with security best practices. Applied the CyberKill Chain methodology to analyze and break down attack stages, enabling proactive detection and mitigation strategies. Ensured adherence to the CIA triad (Confidentiality, Integrity, Availability) while analyzing incidents and recommending security controls. Developed custom scripts (Python/PowerShell) within SOAR platforms to extend automation capabilities and support complex use cases. Investigated and responded to insider threats and data exfiltration incidents using DLP and UEBA tools. Automated repetitive SOC tasks using scripting (PowerShell/Bash) to enhance operational efficiency and incident response speed. Monitored real-time security alerts across SIEM and EDR consoles, performing first-level triage and severity classification. Logged, tracked, and escalated confirmed incidents through ServiceNow and JIRA per SOC SLA requirements. Assisted senior analysts with log analysis across authentication, endpoint, and network sources to support active investigations. Performed initial IOC lookups using open-source threat intelligence tools to validate suspicious IPs, domains, and file hashes. Gained foundational exposure to Linux system logs, Windows Event Logs, and basic PowerShell scripting for evidence gathering. Documented daily shift handover reports and contributed to knowledge-base articles for recurring alert patterns.

Education

B.Tech โ€“ Electronics & Communication Engineering (ECE) - Avanthi Institute of Engineering and Technology, JNTU-Kakinada

- 2021 ยท Afghanistan

Certifications

No certifications added yet

Interested in this developer?

Profile Score Breakdown

๐Ÿ“ท Photo 10/10
๐Ÿ“„ Resume 10/10
๐Ÿ’ผ Job Title 10/10
โœ๏ธ Bio 10/10
๐Ÿ› ๏ธ Skills 20/20
๐ŸŽ“ Education 10/10
โฑ๏ธ Experience 14/15
๐Ÿ’ฐ Rate 0/5
๐Ÿ† Certs 0/5
โœ… Verified 5/5
Total Score 89/100

Profile Overview

Member sinceJul 2026