Back to Developers
Chaitanya Prabhakar Kundampudi

Chaitanya Prabhakar Kundampudi

Cyber Security professional

Visakhapatnam 8+ yrs exp 90 ยท Outstanding

About

Results-driven Cyber Security professional with 8+ years of IT experience, including 7+ years in Security Operations (SOC), SIEM monitoring, and incident response. Experienced in analyzing and investigating security events, improving detection quality, and supporting 24x7 SOC operations across enterprise environments. Strong expertise in security event analysis, log monitoring, and incident management across network, endpoint, and cloud platforms, with a solid understanding of threat detection techniques and attack patterns. Skilled in alert tuning, root cause analysis, and enhancing overall security posture. Hands-on experience in incident investigation including phishing analysis, malware analysis, and threat intelligence enrichment, with the ability to provide actionable remediation recommendations. Familiar with integrating multiple log sources and working with diverse security tools across SIEM, SOAR, and endpoint security domains, along with intermediate-level experience in digital forensics and vulnerability assessment to support deeper security investigations and risk identification. Proven ability to collaborate with cross-functional teams, handle L2/L3 escalations, and contribute to continuous improvement of SOC processes, documentation, and reporting. A proactive team player with strong analytical, communication, and problem-solving skills, capable of managing multiple priorities in high-pressure environments.

Skills & Expertise (43)

Azure Sentinel Advanced
8.5/10
2
Years Exp
MITRE ATT&CK framework Advanced
8.5/10
4
Years Exp
Splunk ES Advanced
8.3/10
4
Years Exp
IBM QRadar Advanced
8.1/10
5
Years Exp
Incident Management Advanced
8.0/10
6
Years Exp
Threat Detection Advanced
8.0/10
6
Years Exp
Log Analysis Advanced
8.0/10
6
Years Exp
Event correlation Advanced
8.0/10
6
Years Exp
Alert Tuning Advanced
8.0/10
8
Years Exp
Microsoft 365 Defender Intermediate
7.0/10
2
Years Exp
ServiceNow Intermediate
7.0/10
3
Years Exp
Jira SLA Adherence Phishing Analysis Malware Analysis Use Case Tuning SOP & Runbook Creation BMC Remedy IBM Resilient SOPs Runbooks Reporting Process Improvement HLD LLD Palo Alto ArcSight Log Normalization Azure AD Azure Firewall Defender for cloud CrowdStrike Falcon Sentinel One Checkpoint Security monitoring CISCO Zscaler Qualys Nessus IDS IPS Web Proxies Antivirus

Work Experience

SIEM Engineer

NTT Data Business Solutions

Apr 2024 - Present

SIEM Engineer experience in handling day-to-day monitoring, alert tuning, and improving detection quality based on SOC feedback using Microsoft Sentinel and Splunk ES. Hands-on experience in SPL queries for log analysis, alert investigation, and security event correlation in Splunk Enterprise Security. Designed and optimized detection frameworks and SIEM correlation rules aligned with MITRE ATT&CK to enhance threat detection coverage and improve alert fidelity. Worked on Microsoft Sentinel to monitor security alerts and investigate incidents in a SOC environment. Created and modified KQL-based analytics rules to detect suspicious activities such as brute force attempts, phishing attacks, and anomalous sign-ins. Integrated data connectors such as Azure AD, Microsoft 365, and firewall logs for centralized log monitoring and improved visibility. Led threat hunting initiatives using EDR/XDR telemetry to identify suspicious activities and potential threats. Implemented SIEM integrations across hybrid environments (on-prem, Azure, AWS, Microsoft 365) to ensure centralized log visibility. Implemented automation workflows to reduce manual effort and improve incident response efficiency (MTTR). Reduced false positives and alert fatigue through correlation logic tuning, use case optimization, and exception handling. Collaborated with cloud, network, and compliance teams to enhance security monitoring across enterprise environments. Led end-to-end incident investigation and response activities, ensuring timely detection, analysis, root cause identification, and remediation recommendations. Monitored and analyzed email threats (phishing, spoofing, malware) and implemented email security controls (SPF, DKIM, DMARC). Acted as SPOC for client onboarding, coordinating with multiple teams to onboard log sources and ensure successful SIEM integration. Led incident response activities in a managed SOC, ensuring SLA adherence, proper escalation, and effective stakeholder communication. Performed vulnerability assessment and remediation tracking using vulnerability management tools, coordinating with teams to address identified risks. Applied intermediate-level digital forensics techniques during incident investigations, including log analysis, evidence collection, and supporting root cause analysis. Administered and supported security technologies and contributed to onboarding of servers and endpoints into SIEM and EDR platforms for comprehensive monitoring.

Senior Security Analyst (L3)

Innova Solutions

Jun 2022 - Mar 2024

Developed and optimized advanced detection use cases using KQL in Microsoft Azure Sentinel and SPL in Splunk Enterprise Security, reducing false positives by approximately 30% and improving detection efficiency. Designed and managed endpoint security solutions including antivirus, host-based firewall, and IDS/IPS controls using endpoint security tools. Monitored network and endpoint environments in a 24ร—7 SOC to detect, investigate, and respond to security incidents within defined SLAs. Developed and mapped detection use cases to the MITRE ATT&CK framework to improve threat visibility and coverage. Analyzed security alerts by aligning them with MITRE ATT&CK techniques for effective investigation and response. Led threat hunting activities leveraging EDR telemetry and SIEM analytics to identify lateral movement, persistence, and anomalous behavior. Conducted vulnerability assessments and coordinated remediation efforts, improving vulnerability closure rates and overall security posture. Ensured endpoint security configurations aligned with security standards through audits and system hardening reviews. Developed and enforced endpoint security policies including password hygiene, email security, and device control standards. Delivered security awareness sessions to end-users, reducing phishing and malware-related incidents. Investigated phishing emails, performed header analysis, and handled email security alerts as part of incident response. Performed root cause analysis (RCA) for medium to high severity incidents and implemented detection improvements to prevent recurrence. Collaborated with network, cloud, and vulnerability management teams to enhance monitoring coverage and streamline incident response.

Associate consultant (SOC/ Security Analyst)

Capgemini

Feb 2021 - Jun 2022

Provided SIEM operations support using IBM QRadar in a 24ร—7 SOC environment, monitoring security events for multiple client environments. Performed first-level incident response and supported the complete incident lifecycle including identification, analysis, containment, and closure. Investigated security alerts in SIEM, performed analysis, and documented findings with recommended actions. Monitored and analyzed logs from firewalls, IDS/IPS, and other security devices to identify suspicious activities and potential threats. Performed basic network traffic analysis using SIEM tools to detect anomalies and security incidents. Investigated phishing and spam-related incidents and supported mitigation actions. Assisted in integration of IBM QRadar with IBM Resilient IRP for improved incident handling and case management. Troubleshot log source and ingestion issues by coordinating with cross-functional teams to ensure log availability. Supported client communication by participating in review calls and providing updates on incidents and activities. Managed and updated incidents in ticketing tools, ensuring proper documentation and SLA adherence. Prepared and delivered daily, weekly, and bi-weekly reports along with monthly dashboards highlighting security incidents and threat trends. Monitored daily threat intelligence feeds and updated IOCs in SIEM reference sets to enhance detection capabilities. Performed alert analysis and contributed to identifying false positives for tuning opportunities. Collaborated with internal teams to improve monitoring coverage and incident response processes. Participated in cyber drills and security exercises, identifying potential threats and supporting response activities. Contributed to documentation, runbooks, and knowledge-sharing initiatives within the SOC team. Acted as shift lead on a rotational basis, coordinating team activities, handling escalations, and ensuring smooth SOC operations.

Service Desk Engineer/Junior security analyst

Happiest Minds

Jan 2018 - Dec 2020

Provided L1/L2 technical support for network and end-user issues, ensuring stable LAN, Wi-Fi, and VPN connectivity across enterprise environments. Diagnosed and resolved network issues including IP configuration, DNS resolution, gateway connectivity, and general connectivity failures. Troubleshot routers and switches for basic connectivity and network performance issues, ensuring minimal downtime. Supported remote users by resolving VPN connectivity, authentication, and access-related issues. Performed system and network troubleshooting using tools and commands such as ping tests, DNS flush, and adapter resets. Installed, configured, and supported Windows and Linux operating systems in user and server environments. Performed system patching activities including OS updates, security patches, and vulnerability fixes to ensure systems are up to date and compliant. Provided remote support via calls and emails, resolving hardware, software, and application-related issues. Maintained security compliance by ensuring antivirus updates, firewall checks, and system-level security configurations. Logged, tracked, and updated incidents in ticketing systems while ensuring SLA adherence and proper documentation. Assisted users with login issues, system access problems, email errors, and basic application troubleshooting. Coordinated with IT teams for escalations and resolution of complex network and system-related incidents. Enforced basic security practices including password policies, secure access control, and user access validation. Monitored security events and alerts in an Offshore SOC environment using IBM QRadar to identify suspicious activities and intrusion attempts. Managed daily log collection from network devices, servers, firewalls, and security tools to ensure proper visibility in the SIEM platform. Analyzed firewalls, proxy, VPN, and endpoint logs to detect unusual behavior and possible security threats. Investigated security incidents and prepared basic security incident reports with findings and recommended mitigation steps. Handled incident, problem, and change management tickets related to network security within agreed SLA timelines.

Education

B. Tech in Information Technology - Sri Prakash College of Engineering, JNTUK

- 2015 ยท Afghanistan

Certifications

No certifications added yet

Interested in this developer?

Profile Score Breakdown

๐Ÿ“ท Photo 10/10
๐Ÿ“„ Resume 10/10
๐Ÿ’ผ Job Title 10/10
โœ๏ธ Bio 10/10
๐Ÿ› ๏ธ Skills 20/20
๐ŸŽ“ Education 10/10
โฑ๏ธ Experience 15/15
๐Ÿ’ฐ Rate 0/5
๐Ÿ† Certs 0/5
โœ… Verified 5/5
Total Score 90/100

Profile Overview

Member sinceJul 2026