Rakesh Jalli palli
Cybersecurity Engineer L2
About
Cybersecurity Engineer with a strong focus on cloud security, incident response, and threat analysis. Proven ability to enhance security posture through effective firewall and web application firewall (WAF) management โ including Zscaler, Cloudflare, and FortiGate โ and endpoint protection.
Skills & Expertise (24)
Work Experience
Cybersecurity Engineer L2
Fujitsu
Apr 2022 - Present
Investigated AWS GuardDuty findings across cloud workloads, triaging threat categories including reconnaissance, credential compromise, and unusual API activity to assess blast radius and initiate containment. Administered Zscaler (ZIA/ZPA) and Zscaler WAF policies to enforce secure web gateway controls, protect internet-facing applications from OWASP Top 10 threats, and provide zero-trust access for remote users. Monitored Zscaler WAF and traffic logs to identify blocked attack attempts, tune WAF rule sets, and reduce false positives while maintaining application availability. Configured Cloudflare for web application protection to block OWASP Top 10 vulnerabilities, manage bot traffic, and enforce rate limiting policies. Provided real-time WAF telemetry from Zscaler and Cloudflare to the SOC team for high-fidelity network detection and rapid response. Resolved network security incidents within SLA, troubleshooting and identifying root cause on FortiGate devices. Used Forti Analyzer for centralized log management, security event correlation, and compliance reporting. Implemented threat detection rules in Microsoft Sentinel to identify advanced threats using built-in analytics and custom KQL-based detection rules. Tuned analytics rules, configured alert suppression, and managed watchlists to improve detection accuracy and reduce noise in client environments. Performed KQL-based threat hunting, root cause analysis, and incident investigations across hybrid enterprise environments. Performed real-time monitoring and triage of alerts from Microsoft Sentinel and Microsoft Defender, investigating phishing, malware, and credential-theft incidents, and conducting root cause analysis. Built Splunk dashboards consolidating security telemetry from firewalls, endpoints, and identity sources, enabling real-time visibility into threat activity and compliance posture for SOC and management reporting. Conducted forensic investigations using Splunk SPL to reconstruct attack timelines, trace anomalous user behavior, and gather evidence in support of incident response and post-incident reviews. Monitored and triaged security alerts in Splunk SIEM as part of daily SOC analyst operations, investigating incidents across endpoint, network, identity, and cloud data sources. Built and optimized Splunk SPL queries to investigate security incidents, perform log analysis, and support threat hunting activities. Monitored endpoint threats using Microsoft Defender for Endpoint to detect malware, ransomware, and suspicious activities. Used Falcon EDR telemetry for threat hunting and IOC investigation across customer environments. Developed and enhanced SOAR workflows and playbooks integrated with CrowdStrike Falcon for automated incident response. Performed endpoint isolation, file quarantine, and IOC blocking during active security incidents. Configured and managed Microsoft Purview DLP policies to prevent unauthorized sharing of sensitive data (PII, PCI, and financial information) across email, endpoints, and cloud applications. Investigated Microsoft Purview DLP alerts and policy match incidents, reviewing activity context and tuning rules and sensitivity labels to reduce false positives while maintaining compliance. Collaborated with compliance and data owners to remediate DLP policy violations and reinforce data handling practices across endpoints and cloud apps. Monitored and investigated phishing alerts, triaging suspicious emails and escalating confirmed threats using Abnormal Security. Analyzed Abnormal Security threat campaign data to identify recurring BEC patterns, spoofed sender infrastructure, and targeted user groups, producing threat intelligence summaries shared with security leadership and client stakeholders. Monitored threat feeds, dark web forums, and malware campaigns to identify emerging risks and track threat actor activity. Managed the full incident lifecycle including triage, containment, escalation, and closure in accordance with SOC playbooks.
Education
B.Tech in Computer Science Engineering - Lovely Professional University (LPU)
- 2020 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (24)
Click a skill to find developers with the same skill