MADHUSUDHANA RAO NAGIDI
Security Analyst
About
Security Analyst with around 2+ years of experience in endpoint and cloud security, SIEM, and SOC operations. Expertise in threat monitoring, malware analysis, incident response, and vulnerability management. Proven track record of implementing innovative security solutions and ensuring compliance with industry standards.
Skills & Expertise (37)
Work Experience
Security Analyst
Capgemini
Aug 2024 - Present
Experience in creating and maintaining the daily, weekly, and monthly reports of device health status by using Defender ATP. Experienced in creating conditional access policies and fine-tuning the ASR rules in Defender 365 and Intune. Configured scheduled and Near Real-Time (NRT) Analytics Rules using KQL. Coordinated vulnerability remediation with infrastructure, server, and application teams using ServiceNow workflows. Correlated Defender XDR incidents with Azure AD Sign-in Logs, Office 365 Logs, and Azure Activity Logs using Microsoft Sentinel. Managed Defender TVM (Threat & Vulnerability Management), prioritising security recommendations and exposure score improvements. Troubleshot Intune device enrollment issues, sync failures, compliance failures, and policy deployment issues. Monitored ransomware groups, malware campaigns, and nation-state threat actors impacting enterprise environments. Experience in conducting and supporting the internal auditing for the soc2 compliance reports. Experienced in conducting investigations of static analysis, dynamic analysis, and IOCs using sandbox environments. Hunt for security threats using Azure Sentinel. Good knowledge of analysing different malicious executables and documents. Escalating security incidents based on the client's SLA and providing meaningful information related to security incidents by conducting in depth analysis of events, which makes the customer's business safe and secure. Experience with compliance tickets and advisory for the blacklisting of IOCs, and processes using Endpoint Security. Configured and maintained URL Filtering, Firewall, SSL Inspection, DNS Security, Bandwidth Control, and Cloud Application policies. Hands-on experience in the installation, configuration, and management of Microsoft Exchange Servers 2016 and above. Investigated inactive devices, unhealthy sensors, missing telemetry, and troubleshooting Defender portal reporting issues. Experience in creating tickets and updating the incident response notes and implementing the automated ticket creation using the servicenow. Experience in performing the Manual scans and scheduled scans and identifying the common vulnerabilities using the Action1 vulnerability management tool. Performed folder exclusion policies, device-based policies, and tags in Defender for Endpoint. Experienced in creating conditional access policies and managing licenses in Azure Entra ID. Conduct in-depth analysis of security events, collaborating directly with customers to escalate and thoroughly investigate incidents. This involves understanding the scope, impact, and root cause of incidents to tailor the response effectively. Performed end-to-end analysis of phishing campaigns using Threat Explorer, Real Time Detections, and Email Entity views. Good hands-on experience in creating custom detection rules using the KQL language and fine-tuning use cases to reduce false positives in Defender 365 and Azure Sentinel. Experience in working on host isolation and advanced threat analysis using the EDR Microsoft Defender ATP. Good hands-on experience in creating the SOPs, playbooks, and runbooks using Splunk and Defender, as well as hands-on experience in creating and managing the endpoint health check reports and vulnerability reports to reduce the exposure score. Handling spam and phishing email submissions from end-users, taking containment steps by further investigating domains and IPs to recommend proper blocking, and creating SPF, DKIM, and DMARC records for the domains to protect against spoofing. Strong knowledge and working experience of Office 365 email gateway solutions, completely owning, managing, monitoring, and administering the email security stack and policies for both on-premises and cloud environments, including Office 365 email security solutions. Creating mail flow rules and policies in the Exchange Admin Centre to block or unblock any kind of sender address, domain, and subject match. Working in the Security Operation Centre (24x7), monitoring SOC events, and detecting and preventing intrusion attempts. Experience in AIR (Automated Investigations and Remediation) policies and their implementation.
Education
B.Tech in AI & Data Science - KL University
- 2024 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (37)
Click a skill to find developers with the same skill