Kiran M
Project Associate
About
Cyber Security professional with around 5 years of hands-on experience in Security Operations Center (SOC), Incident Monitoring, Threat Detection, Incident Response, and Security Event Analysis. Experienced in monitoring and investigating alerts through SIEM tools such as Microsoft Sentinel, Splunk, and IBM QRadar. Strong knowledge in alert triage, log analysis, false positive reduction, phishing investigation, IOC analysis, endpoint security, and threat hunting. Hands-on experience with security devices and logs including Firewalls, IDS/IPS, WAF, Proxy, Antivirus, and EDR solutions. Good understanding of incident lifecycle management, ticket handling, escalation procedures, and root cause analysis. Familiar with MITRE ATT&CK framework, vulnerability management, and best practices for improving security posture. Strong analytical, troubleshooting, and communication skills.
Skills & Expertise (49)
Work Experience
Project Associate
Unilog Content Solutions
Apr 2021 - Present
Performed regular and ad-hoc threat hunting activities using EDR and SIEM tools to identify potential threats before exploitation. Conducted hypothesis-driven threat hunting and IOC-based investigations across endpoints and network environments. Developed, tuned, and maintained SIEM correlation rules/use cases to improve threat detection coverage. Performed real-time monitoring, investigation, analysis, reporting, and escalation of security events from multiple log sources. Monitored security alerts from IPS, Firewalls, DLP, Endpoint Security, Operating Systems, Email Security, Servers, and VPN devices. Reviewed automated daily security events, identified anomalies, and escalated critical incidents to relevant IT teams for remediation. Investigated alerts in SOC monitoring tools to identify abnormal behavior, suspicious activities, and traffic anomalies. Analyzed network traffic and host activities across a wide range of technologies and platforms. Analyzed employee-reported phishing emails and classified them as phishing, spam, or legitimate messages. Monitored email traffic for malicious threats and investigated suspicious communications. Responded to cloud security alerts and logs from Amazon Web Services CloudTrail, CloudWatch, GuardDuty, and Defender for Cloud. Managed endpoint security incidents involving malware, ransomware, and suspicious endpoint activities. Assisted in incident response activities including host triage, evidence retrieval, malware analysis, remediation, and user coordination. Performed end-to-end incident response, root cause analysis (RCA), and acted as Incident Commander during major incidents. Reduced false positives by fine-tuning SIEM rules/use cases and resolving log parsing issues. Performed daily SIEM health checks to ensure all devices were forwarding logs properly and troubleshot ingestion issues. Created security reports, dashboards, KPIs, and routine daily/weekly/monthly/quarterly/yearly metrics for management. Developed SOC documentation, SOPs, knowledge articles, and best practice guides for analysts on Microsoft Sentinel usage and search techniques. Implemented Recorded Future and integrated it with Microsoft Sentinel for threat intelligence correlation and detection. Performed vulnerability assessments using Qualys VM, prioritized findings using CVSS, and coordinated patch remediation. Led migration from FireEye Helix to CrowdStrike EDR, including sensor upgrades, IOC management, custom IOA creation, and prevention policy administration. Managed and administered advanced endpoint protection tools including CrowdStrike. Conducted proof of concept (POC) evaluations for SentinelOne and Palo Alto Networks Cortex XDR solutions. Performed vendor evaluations for SOAR platforms such as Cortex XSOAR, Splunk Phantom, Microsoft Sentinel, and FortiSOAR. Coordinated with L1 analysts and cross-functional teams including NOC, Server, EUS, and Windows teams during escalations, while providing KT sessions and incident guidance. Took action on threat advisories and IOCs, mapped threats using MITRE ATT&CK, and coordinated IOC blocking/containment activities.
Data Analyst
Unilog Content Solutions
Aug 2014 - Mar 2021
Started career as an intern and progressed into a full-time employee based on performance and business contribution. Provided consulting support to customers by creating custom reports, dashboards, and data solutions based on business requirements. Performed data enrichment, data cleansing, and content management for e-commerce product catalogs. Managed and maintained master data across multiple systems to ensure data accuracy, consistency, and completeness. Integrated data from multiple sources into centralized systems while ensuring data quality and accessibility. Identified and corrected inaccuracies, inconsistencies, duplicates, and missing values in datasets. Generated MIS reports, statistics, and performance dashboards for management review and decision-making. Utilized advanced Microsoft Excel functions, Microsoft Power BI, and Microsoft PowerPoint for data analysis, reporting, and visualization. Maintained logs, audit trails, and records to track data changes, updates, and access history. Supported adherence to data governance standards, internal policies, and quality control procedures. Coordinated with internal teams and stakeholders to resolve data issues and improve process efficiency. Performed regular data validation checks to maintain integrity across business systems.
Education
Bachelor of Engineering - Vidya Vikas Institute of Engineering & Technology
- ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (49)
Click a skill to find developers with the same skill