Lakshmi
SOC L1/L2 Analyst
About
Self-motivated cybersecurity professional with 4+ years of experience in Security Operations, Incident Response, and Vulnerability Management. Seeking a challenging SOC L1/L2 Analyst role to leverage expertise in SIEM, threat intelligence, and vulnerability lifecycle management while continuously enhancing organizational security posture.
Skills & Expertise (21)
Work Experience
Advanced Analyst
UnitedLex
Apr 2024 - Jun 2026
Performed SIEM monitoring using Splunk ES and Hunters, conducting alert triage, enrichment, and prioritization. Investigated security incidents by correlating logs from EDR, firewalls, proxies, and Azure Activity Logs. Analyzed IOCs (IPs, domains, and hashes) using threat intelligence to validate malicious activity. Executed incident response actions including endpoint isolation, credential disablement, and IOC blocking. Conducted phishing investigations using KnowBe4 and Defender for Office 365, including email header analysis and URL inspection. Applied MITRE ATT&CK to map attacker techniques and improve incident classification. Performed threat hunting using SIEM queries to detect anomalies and hidden threats. Managed the vulnerability lifecycle using InsightVM Rapid7. Documented incident analysis, root cause analysis (RCA), and remediation steps in ServiceNow/Jira. Tuned SIEM detection rules to improve alert quality and reduce false positives. Administered a single-site Splunk Indexer Cluster using a Cluster Manager to enforce Replication Factor (RF) and Search Factor (SF). Coordinated cluster-wide configuration bundles, validating and pushing system updates, indexes, and parsing rules to peer indexers. Managed bucket lifecycles across hot, warm, cold, and frozen states using indexes.conf to optimize storage and meet retention requirements. Monitored cluster health and resource utilization using Splunk Monitoring Console to resolve ingestion queues and hardware bottlenecks. Scaled the single-cluster architecture by onboarding new indexer peers to distribute ingestion loads and improve search concurrency. Used a centralized Deployment Server to manage configuration apps, server classes, and inputs for Universal Forwarders. Configured load-balanced forwarder routing through outputs.conf across available indexer peers. Onboarded Windows/Linux event logs, network firewalls, cloud logs, and application APIs. Authored regular expressions in props.conf and transforms.conf to mask sensitive data, break lines, and extract fields at ingestion time. Implemented RBAC by integrating Splunk with Active Directory/LDAP and SAML for SSO. Optimized daily Splunk license consumption by configuring null queues to discard unnecessary log noise. Rewrote inefficient SPL queries to improve search execution times and overall SOC investigation efficiency. Installed and tuned Splunk Technology Add-ons (TAs), ensuring ingested data complied with the Common Information Model (CIM). Analyzed network traffic across DNS, HTTP/S, and SMTP to identify anomalies and suspicious activity.
Technical Support Engineer
Crest Data Systems Pvt. Ltd.
Dec 2023 - Mar 2024
Monitored SIEM and security tools to identify and investigate security events. Administered on a single-site Indexer Cluster using a Cluster Manager to enforce replication and search factors (RF/SF). Coordinated cluster-wide configuration bundles, validating and pushing system updates, indexes, and parsing rules to peer indexers. Managed bucket lifecycles across hot, warm, cold, and frozen states in indexes.conf to optimize storage and retention. Monitored cluster health and resource utilization using Splunk Monitoring Console to resolve ingestion queues and hardware bottlenecks. Scaled the single-cluster architecture by onboarding new indexer peers to distribute ingestion loads and improve search concurrency. Conducted vulnerability scans using Rapid7 and supported remediation efforts. Managed endpoint security using Microsoft Defender and SentinelOne. Performed log correlation across firewalls, IDS/IPS, and endpoints. Investigated phishing and malware incidents, implementing IOC-based blocking. Generated security and compliance reports for stakeholders.
Support IT Analyst
CMA-CGM
Apr 2022 - Nov 2023
Monitored Splunk SIEM and DLP tools, performing initial triage and escalation. Implemented RBAC by integrating Splunk with Active Directory/LDAP and SAML for SSO. Optimized daily license consumption by configuring null queues to discard unnecessary log noise. Assisted SOC analysts and developers by rewriting inefficient SPL queries to improve search execution times. Installed and tuned Splunk Technology Add-ons (TAs), ensuring ingested data complied with the Common Information Model (CIM). Investigated authentication anomalies and unauthorized access attempts. Conducted log analysis across VPN, endpoint, and system logs. Managed incidents using ServiceNow, ensuring full lifecycle tracking. Performed SOC operational checks (SOD/EOD). Contributed to incident documentation and knowledge base improvements.
Education
B.Tech in Computer Science Engineering - Lovely Professional University
2016 - 2020 ยท India
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (21)
Click a skill to find developers with the same skill