Rajavardhan
Security Analyst
About
Cybersecurity professional with 02 years of experience in SOC operations, specializing in threat detection, incident response, and security monitoring across enterprise environments. Extensive hands-on expertise in SIEM platforms including Microsoft Sentinel, Splunk, analyzing large-scale security events to identify and mitigate potential threats. Proven ability to manage the complete incident lifecycle—from alert triage and investigation to containment, recovery, and post-incident reporting—ensuring timely resolution of security incidents. Strong background in threat hunting and detection engineering, leveraging KQL queries, Sentinel analytics rules, and MITRE ATT&CK techniques to improve detection coverage and reduce false positives. Experienced in security monitoring across multiple log sources including EDR, firewall, cloud logs, IDS/IPS, and email security platforms to detect sophisticated attack patterns. Demonstrated leadership capability by guiding SOC analysts, mentoring junior team members, and ensuring operational continuity through effective shift management and documentation practices. Hands-on expertise in email security and phishing investigation using tools such as Microsoft Defender for O365, Mimecast, and PhishER, enabling rapid identification and containment of malicious campaigns. Skilled in developing and optimizing SOC use cases, playbooks, dashboards, and automation workflows to enhance operational efficiency and strengthen threat response capabilities. Collaborative professional who works closely with SOC engineers, IT, cloud, and network teams to validate incidents, onboard new log sources, and strengthen overall security posture. Holds SC-200 and Fortinet Certified Associate certifications, combining strong analytical investigation skills with practical security operations experience to defend organizations against evolving cyber threats.
Skills & Expertise (21)
Work Experience
Security Analyst
Capgemini
May 2024 - Present
Skilled in security monitoring, incident response, and threat investigation using Microsoft Sentinel and the Microsoft Defender security suite. Handles the end-to-end incident lifecycle, including alert triage, deep investigation, containment, eradication, and recovery while ensuring proper documentation and escalation. Creates and fine-tunes Sentinel analytics rules, KQL queries, and automated playbooks to enhance detection accuracy, reduce false positives, and automate incident response processes. Leads a team of SOC analysts in investigating phishing attacks, malware infections, insider threats, privilege misuse, and suspicious user activities across endpoints, network, and cloud environments. Performs proactive threat hunting using Sentinel hunting queries and integrates MITRE ATT&CK techniques to improve detection coverage and identify hidden threats. Conducts deep-dive investigation of alerts generated from SIEM, EDR, firewall, DLP, CASB, and cloud security logs to determine true positive and false positive cases. Coordinates with IT, Cloud, Endpoint, and Network teams to support incident response activities, containment actions, and remediation efforts. Collaborates with SOC engineers for log onboarding, use-case development, detection tuning, and SIEM optimization to improve overall SOC efficiency. Prepares incident summary reports, threat advisories, and SOC dashboards to track security metrics, trends, and operational performance. Mentors junior analysts, ensures proper shift handovers, runbook adherence, and SOC documentation standards, while continuously improving SOC processes, automation, and proactive threat defense strategies.
Education
B. Tech - JNTU Anantapur
- · Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Citizen
Relocation
Open to Relocation
Skills (21)
Click a skill to find developers with the same skill