About
IT Security Professional with 3.7 years of overall IT experience, including 2 years of hands-on experience in Security Operations Center (SOC) environments. Skilled in Security monitoring, alert triage, incident investigation, phishing analysis, malware analysis, threat detection and initial response to security incidents. Familiar with Splunk, Microsoft Sentinel, Microsoft Defender, Wireshark, ServiceNow, VirusTotal, AbuseIPDB, and Any.Run. Strong understanding of SOC processes, Security tools, TCP/IP, DNS, DHCP, HTTP/HTTPS, VPN, firewalls, IDS/IPS, Active Directory, Windows security events, MITRE ATT&CK, Cyber Kill Chain, CIA Triad, and incident response lifecycle.
Skills & Expertise (55)
Work Experience
Associate Software Engineer
Mphasis Limited
Feb 2022 - Oct 2025
Triaged and Investigated security incidents across Splunk, Sentinel, Microsoft Defender for Endpoint in 24x7 enterprise SOC environment. Performed alert triage by validating source IP, destination IP, username, hostname, timestamp, event type, and related indicators. Investigated failed and successful authentication patterns to identify potential brute-force and credential-based attacks. Used MITRE ATT&CK techniques to map observed attacker behavior. Investigated suspicious IP addresses, domains, URLs, and file hashes using VirusTotal and AbuseIPDB. Documented investigation findings, indicators of compromise, severity, recommended actions, and escalation requirements. Analyzed suspicious emails and identified phishing indicators including spoofed senders, malicious URLs, suspicious attachments, and social-engineering techniques. Performed email-header analysis and investigated suspicious domains and URLs using threat intelligence platforms. Analyzed suspicious files using sandbox environments and extracted IOCs including IP addresses, domains, URLs, file names, and hashes. Monitored Azure Security alerts and analyzed sign logs, detecting anomalous user behavior threats. Investigated credential compromise and suspicious login cases, escalating confirmed incidents with recommended remediation steps. Analyzed brute-force attempts across cloud and on premises environments on identity-based attacks. Captured and analyzed network traffic using Wireshark. Investigated TCP connections, DNS queries, HTTP traffic, source/destination IP addresses, and network protocols. Analyzed TCP three-way handshake and abnormal connection behavior. Investigated suspicious DNS requests and potential indicators of DNS tunneling. Analyzed Windows security logs for authentication, privilege, account, and process-related activity. Investigated successful and failed authentication patterns and practiced identifying potential account compromise. Created investigation notes containing timestamp, user, source IP, hostname, event ID, activity, and recommended action. Supported enterprise IT operations in a large corporate environment, handling software requests, incidents, changes, approvals, compliance activities, and technical escalations. Used ServiceNow for incident/request management, ticket tracking, workflow monitoring, documentation, and issue escalation. Worked in Software Asset Management Team for 1+ years of experience, supporting software lifecycle management from request and approval through deployment, compliance validation, and retirement. Reviewed software requests and coordinated security/compliance approvals before software deployment. Reviewed vulnerability assessment reports received from security/threat management teams and supported remediation tracking for compliance requirements. Monitored emails, Teams communications, ServiceNow queues, and operational dashboards to identify pending issues and ensure timely response. Maintained operational documentation, software records, compliance information, and technical reports in centralized repositories. Worked with cross-functional teams to investigate technical issues, collect relevant information, document findings, and escalate unresolved issues. Supported privileged-access workflows involving CyberArk for controlled access to enterprise systems.
Education
B.Tech in Computer Science Engineering - Kasireddy Narayan Reddy College of Engineering and Research - JNTUH
- 2020 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Need Sponsorship
Relocation
Open to Relocation
Skills (55)
Click a skill to find developers with the same skill