Nagarajukalavala
Security Analyst
About
Security Analyst with 3 years of progressive experience in cybersecurity. Skilled in monitoring, triaging, and investigating security alerts, as well as responding to cybersecurity threats using Splunk, Microsoft Sentinel, CrowdStrike Falcon and Microsoft Defender. Strong knowledge of SIEM, EDR, email security, and network threat detection. Demonstrated ability to strengthen security posture through proactive threat monitoring, in-depth analysis, and effective cross-team collaboration.
Skills & Expertise (24)
Work Experience
Security Analyst
DB Schenker
Oct 2025 - Present
Hands-on experience in analyzing the device timeline logs and pulling reports by using advanced hunting in KQL. Monitored, analyzed, and triaged security events generated from the Sentinel SIEM platform, ensuring timely detection of suspicious activities and potential threats. Built and maintained incident response playbooks using Azure Logic Apps, automating alert triage, ticket creation, and email notifications. Investigated and resolved phishing, malware, credential abuse, and endpoint compromise incidents, including device isolation, user investigation, IOC Enrichment, and remediation actions. Experience in working on host isolation and advanced threat analysis using EDR, Microsoft Defender ATP. Monitored agent status and performance via the Microsoft Defender portal, proactively identifying and resolving issues such as outdated signatures, disabled real-time protection, and other vulnerabilities. Experienced in triaging Defender alerts, performing root cause analysis, and generating incident reports for executive stakeholders. Conducted static and dynamic malware analysis to extract IOCs, understand malware behavior, and recommend mitigation strategies. Investigated quarantined emails flagged by EDR tools (Microsoft Defender), releasing safe messages and blocking malicious ones to prevent phishing attacks. Monitored and triaged insider threats and User Entity Behavioral Analytics (UEBA), creating reports and dashboards, and fine-tuning rules (alert fine-tuning). Creating and fine-tuning use cases and custom detection rules by using KQL in Defender portal. Good knowledge of the MITRE ATT&CK framework, the diamond model, and other cyber threat kill chains. Experience in managing Defender firewall policies, device exceptions, and other security rules via the Microsoft Intune portal. File blocking, virus definition reporting, and end-point reporting. Experience in creating Log Analytics workspaces, creating conditional access policies, and detection rules using Microsoft 365 Defender and Azure Sentinel. Managed incident lifecycle in ITSM systems (ServiceNow), ensuring accurate logging, triage, documentation, and closure of tickets. Collaborated with IT departments to update security software and patch vulnerable systems. Conducted threat hunting using indicators of compromise (IOCs) from threat intelligence sources.
SOC Analyst
TCS
Jun 2023 - Sep 2025
Maintained accurate records of incidents, investigations, and security-related activities within the incident management platform. Experience in vulnerability assessments. Evaluated and prioritized identified vulnerabilities for remediation by collaborating directly with customers. Took appropriate action based on advisories, IOCs, identifying threat actors using MITRE ATT&CK, and coordinating with the respective team to block the IOCs. Continuously monitoring and interpreting threats using the IDS and SIEM tools. In-depth understanding of the latest techniques used by attackers for persistence, privilege escalation, defense evasion, and lateral movement. Managed incident response activities, including investigation and reporting of security breaches. Conducted investigations on infrastructure through forensic analysis to identify Indicators of Compromise (IOCs). Performing real-time monitoring, investigation, analysis, reporting, and escalations of security events from multiple log sources. Hands-on experience (L2 level) in support, implementation, configuration, and management of EDR/AV solutions (EDR/AV solutions like CrowdStrike and Symantec AV). Strong knowledge and working experience of Office 365 Email gateway solutions, completely owning, managing, monitoring, and administering the email security stack and policies for both on-premises and cloud environments, which include Office 365 Email security solutions. Researched new concepts and presented them to the internal team, as well as to customers. Experience in adding and deploying a client onboarding configuration file, Configuration Manager can monitor deployment status, and Microsoft Defender ATP agent health. Create detailed reports on security incidents, response actions taken, and recommendations for improvement. Experienced in identifying, detecting, and responding to security incidents and threats, in accordance with the defined policies and procedures in Security Operations. Blocking and enabling the warning/unsafe Smart Screen alerts for the end users for the detected phishing URLs, malware files, and IPs on Defender.
Education
B.Tech in E.C.E - IIIT, Srikakulam
- 2022 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Relocation
Open to Relocation
Skills (24)
Click a skill to find developers with the same skill