Back to Developers
srinivas srinu

srinivas srinu

Soc Analyst L1

Hyderabad, India 3+ yrs exp 87 ยท Excellent

About

IT Security Professional with 3.7 years of overall IT experience, including 2 years of hands-on experience in Security Operations Center (SOC) environments. Skilled in Security monitoring, alert triage, incident investigation, phishing analysis, malware analysis, threat detection and initial response to security incidents. Familiar with Splunk, Microsoft Sentinel, Microsoft Defender, Wireshark, ServiceNow, VirusTotal, AbuseIPDB, and Any.Run. Strong understanding of SOC processes, Security tools, TCP/IP, DNS, DHCP, HTTP/HTTPS, VPN, firewalls, IDS/IPS, Active Directory, Windows security events, MITRE ATT&CK, Cyber Kill Chain, CIA Triad, and incident response lifecycle.

Skills & Expertise (55)

Security monitoring Advanced
8.1/10
3.7
Years Exp
Incident Response Advanced
8.0/10
3.7
Years Exp
MITRE ATT&CK Advanced
8.0/10
3.7
Years Exp
Log Analysis Advanced
7.8/10
3.7
Years Exp
Splunk Intermediate
7.5/10
3.7
Years Exp
Microsoft Sentinel Intermediate
7.5/10
3.7
Years Exp
Incident Management Intermediate
7.5/10
3.7
Years Exp
PowerShell Intermediate
6.5/10
3.7
Years Exp
Basic Python Intermediate
6.5/10
3.7
Years Exp
CIA Triad Microsoft Defender for cloud Cyber Kill Chain Hash Analysis IOC Analysis Sandbox Analysis IPvoid URLvoid AbuseIPDB ANY.RUN DLP Phishing Analysis Microsoft Azure Proxy ServiceNow Request Management Change Management Ticketing SLA Monitoring Documentation Bash HTTP Alert Triage Incident Identification Incident analysis escalation Case Management Microsoft Defender for Endpoint SentinelOne TCP IP OSI Model DNS DHCP VirusTotal HTTPS ICMP VPN NAT PAT Firewalls IDS IPS WAF ACL WIRESHARK

Work Experience

Associate Software Engineer

Mphasis Limited

Feb 2022 - Oct 2025

Triaged and Investigated security incidents across Splunk, Sentinel, Microsoft Defender for Endpoint in 24x7 enterprise SOC environment. Performed alert triage by validating source IP, destination IP, username, hostname, timestamp, event type, and related indicators. Investigated failed and successful authentication patterns to identify potential brute-force and credential-based attacks. Used MITRE ATT&CK techniques to map observed attacker behavior. Investigated suspicious IP addresses, domains, URLs, and file hashes using VirusTotal and AbuseIPDB. Documented investigation findings, indicators of compromise, severity, recommended actions, and escalation requirements. Analyzed suspicious emails and identified phishing indicators including spoofed senders, malicious URLs, suspicious attachments, and social-engineering techniques. Performed email-header analysis and investigated suspicious domains and URLs using threat intelligence platforms. Analyzed suspicious files using sandbox environments and extracted IOCs including IP addresses, domains, URLs, file names, and hashes. Monitored Azure Security alerts and analyzed sign logs, detecting anomalous user behavior threats. Investigated credential compromise and suspicious login cases, escalating confirmed incidents with recommended remediation steps. Analyzed brute-force attempts across cloud and on premises environments on identity-based attacks. Captured and analyzed network traffic using Wireshark. Investigated TCP connections, DNS queries, HTTP traffic, source/destination IP addresses, and network protocols. Analyzed TCP three-way handshake and abnormal connection behavior. Investigated suspicious DNS requests and potential indicators of DNS tunneling. Analyzed Windows security logs for authentication, privilege, account, and process-related activity. Investigated successful and failed authentication patterns and practiced identifying potential account compromise. Created investigation notes containing timestamp, user, source IP, hostname, event ID, activity, and recommended action. Supported enterprise IT operations in a large corporate environment, handling software requests, incidents, changes, approvals, compliance activities, and technical escalations. Used ServiceNow for incident/request management, ticket tracking, workflow monitoring, documentation, and issue escalation. Worked in Software Asset Management Team for 1+ years of experience, supporting software lifecycle management from request and approval through deployment, compliance validation, and retirement. Reviewed software requests and coordinated security/compliance approvals before software deployment. Reviewed vulnerability assessment reports received from security/threat management teams and supported remediation tracking for compliance requirements. Monitored emails, Teams communications, ServiceNow queues, and operational dashboards to identify pending issues and ensure timely response. Maintained operational documentation, software records, compliance information, and technical reports in centralized repositories. Worked with cross-functional teams to investigate technical issues, collect relevant information, document findings, and escalate unresolved issues. Supported privileged-access workflows involving CyberArk for controlled access to enterprise systems.

Education

B.Tech in Computer Science Engineering - Kasireddy Narayan Reddy College of Engineering and Research - JNTUH

- 2020 ยท Afghanistan

Certifications

No certifications added yet

Interested in this developer?

Profile Score Breakdown

๐Ÿ“ท Photo 10/10
๐Ÿ“„ Resume 10/10
๐Ÿ’ผ Job Title 10/10
โœ๏ธ Bio 10/10
๐Ÿ› ๏ธ Skills 20/20
๐ŸŽ“ Education 10/10
โฑ๏ธ Experience 12/15
๐Ÿ’ฐ Rate 0/5
๐Ÿ† Certs 0/5
โœ… Verified 5/5
Total Score 87/100

Profile Overview

Member sinceOct 2026

Availability Details

Visa Status

Need Sponsorship

Relocation

Open to Relocation