About
Cybersecurity professional with 4 years of experience spanning SOC operations and Android malware reverse engineering. Microsoft Certified: Security Operations Analyst Associate (SC-200), with hands-on expertise in threat detection and incident response using Microsoft Sentinel, Defender XDR, and SentinelOne. Skilled in static and dynamic malware analysis and APK reverse engineering, with experience building automated detection models to identify emerging Android threats at scale. Known for MITRE ATT&CK-aligned investigations and strengthening security posture through cross-functional collaboration.
Skills & Expertise (22)
Work Experience
Security Analyst
Cognizant Private Limited - Client: Clario Life Sciences
Sep 2023 - Present
Monitored real-time security events using Microsoft Azure Sentinel, writing KQL queries to detect anomalies, investigate sign-in logs, and identify suspicious network activity. Tuned Sentinel analytics rules and alert thresholds, reducing false positives and improving overall SOC detection accuracy. Conducted endpoint detection, forensic analysis, and remediation using Microsoft Defender XDR and SentinelOne, resolving multiple malware infections annually. Analyzed 200+ phishing emails monthly via Microsoft O365, performing header inspection, URL tracing, and sandboxing to reduce click-through rates. Tracked incidents end-to-end via ServiceNow and Jira, maintaining forensic evidence and compliance-ready closure reports. Developed KQL detection rules to identify malware indicators, including suspicious process executions and malicious IP communications across endpoint telemetry. Supported a client SOC environment as an embedded L2 resource, handling monitoring, alerting, incident response, reporting, and threat intelligence. Mentored junior analysts on threat investigation, documentation, and triage procedures, improving overall SOC operational maturity. Managed incident detection, client communication, and vendor coordination for security escalations. Administered identity and endpoint security controls via Microsoft Intune and Active Directory, including reviewing user access logs, revoking compromised sessions, and enforcing password resets to contain account takeover risks. Performed L2 triage, root cause analysis, and multi-source log correlation to accurately escalate true positives, while partnering with L3 analysts to build and refine Sentinel analytics rules and expand detection coverage. Participated in 24/7 on-call rotations, leading response to high-impact incidents and ensuring timely containment and stakeholder updates. Designed and implemented custom Logic Apps workflows in Microsoft Sentinel to automate incident triage, enrichment, and response actions. Added indicators of compromise (IOCs), hashes, and IPs into Defender, and created custom spam and allow/block-list policies to reduce phishing exposure.
Malware Analyst
Cognizant Private Limited - Client: Google Play Protect
Aug 2022 - Aug 2023
Performed static and dynamic reverse engineering of Android APKs to detect code obfuscation, malicious payloads, and threat indicators. Categorized malware by threat type and behavioral patterns, conducting bulk analysis to identify potentially harmful applications (PHAs) and emerging trends on the Google Play Store. Developed and optimized Google SQL-based classification rules (analogous to YARA) for large-scale automated Android malware detection. Reviewed Android application source code for security policy violations, vulnerabilities, and compliance gaps against enterprise security standards. Prepared detailed malware analysis reports highlighting IOCs, threat severity, and mitigation strategies for clients and internal stakeholders. Collaborated with cross-functional teams to assess Google Bard AI-generated content for security risks and safety compliance standards. Documented malware trends, detection methodologies, and reverse engineering findings to continuously improve detection rules and response playbooks.
Education
Bachelor of Technology - Computer Science & Engineering - Gandhi Institute of Technology & Management
2018 - 2022 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (22)
Click a skill to find developers with the same skill