Back to Developers
Nikhil kumar

Nikhil kumar

Associate Security Analyst

Hyderabad
80
Profile Score

About

Detail-oriented and precision-focused Associate Security Analyst with 3.7+ years of experience monitoring, detecting and triaging security incidents in fast-paced enterprise environments. Skilled in SIEM log analysis, endpoint investigations, threat intelligence enrichment and incident escalation. Strong understanding of security concepts like OWASP 10, MITRE ATT&CK, kill chain analysis, common attack vectors, malware behaviour and security best practices. Proven ability to reduce false positives, strengthen alert workflows and strengthen overall security posture.

Skills & Expertise (63)

SIEM Analysis Advanced
8.3/10
3.7
Years Exp
Security monitoring Advanced
8.3/10
3.7
Years Exp
Incident Response Advanced
8.1/10
3.7
Years Exp
Endpoint Security Advanced
8.0/10
3.7
Years Exp
Threat Intelligence Research Advanced
7.8/10
3.7
Years Exp
HaveIBeenPawned DHCP DNS OSI Model TCP/IP WAN LAN HIPS/HIDS IDS / IPS DNS dumpster VPN Fortiguard web filter MXtool box MHA header HTTP HTTPS Hybrid Analysis NAT TLS/SSL Firewall Routing and Switching fundamentals Traffic mirroring ItIl NIST ISO 27001 AWS GCP PowerShell Python Microsoft 0365 Alert Triage log correlation Malware Triage Network Traffic Analysis Vulnerability Identification Report Writing Documentation Splunk QRadar Microsoft Sentinel CrowdStrike Falcon Microsoft Defender Nessus Qualys URL void Mimecast ServiceNow Windows LINUX Ubuntu Cent OS Virus Total Anyrun CISCO Talos AbuseIPDB URLScan.io IPvoid URLhaus

Work Experience

Associate Security Analyst

UNIFIED POINTS TECH

Jun 2022 - Present

Monitored SIEM platform (Splunk,Qradar) according to severity and triaged alerts and SOC SLA's. Conducted log analysis of windows, Linux, Firewall, proxy, IDS/IPS and EDR telemetry to identify suspicious behaviour. Investigated phishing attempts, malware detections, brute-force attacks and abnormal authentication activity. Used Crowdstrike / Microsoft defender for endpoint to verify detections, isolate endpoints and collect forensic data. Performed IOC enrichment using Virus Total, Anyrun, Talos, AbuseIPDB and other TI sources. Worked on Microsoft O365 email gateway and responsible for analysis of phishing, spam emails. Using Nessus for vulnerability assessment which include assessing the vulnerability status and escalating same to the vulnerability management team and ensuring proper patch management. Upon containing hosts on high severity incidents, I have also requested for incident response (IR) team involvement for taking responsive actions. Contributed to SOC playbook improvements and documented repeatable investigation workflows. Participated in structured threat hunting activities to proactively identify anomalies and potential threats. Performed Root Cause Analysis (RCA) and appropriately handled incidents as per defined incident management framework. Designed, tuned and maintained SIEM detection rules, dashboards and visualizations to enhance threat detection accuracy and reduce false positives. Monitored and investigated DLP alerts across email, endpoint, web and cloud channels to identify potential data exfiltration. Basics of scripting on powershell and python. Worked on ServiceNow, closing the tickets as per SLA. Follow up the incident till the closure. Contacting the customers directly in case of high priority incidents and helping the customer in the process of mitigating the attacks. Creation of daily, weekly and monthly reports summarizing security incidents, alerts and response actions for stake holders.

Education

Bachelor's Degree in Technology - Kakatiya institute of technology and science

- · Afghanistan

Interested in this developer?

Profile Score Breakdown

📷 Photo 10/10
📄 Resume 10/10
💼 Job Title 10/10
✍️ Bio 10/10
🛠️ Skills 20/20
🎓 Education 10/10
⏱️ Experience 5/15
💰 Rate 0/5
🏆 Certs 0/5
Verified 5/5
Total Score 80/100

Profile Overview

Member sinceFeb 2026

Skills (63)

SIEM Analysis Security monitoring Incident Response Endpoint Security Threat Intelligence Research HaveIBeenPawned DHCP DNS OSI Model TCP/IP +53 more