Back to Developers
sai kumar

sai kumar

Senior Security Analyst

Bangalore, India
80
Profile Score

About

Cyber Security professional with 4.5 years of hands-on experience in SOC operations, SIEM monitoring, incident response, vulnerability management, endpoint security, and email security across enterprise environments. Proven expertise in Azure Sentinel, IBM QRadar, LogRhythm, Splunk, Qualys, Nessus, Proofpoint, FortiGate, EDR tools, and ServiceNow. Adept at threat detection, incident investigation, MITRE ATTCCK mapping, SIEM tuning, and compliance-driven security operations. Strong experience working in 24x7 SOC environments supporting global clients.

Skills & Expertise (39)

SOC Operations Advanced
8.4/10
3
Years Exp
SIEM Monitoring Advanced
8.4/10
3
Years Exp
Incident Response Advanced
8.2/10
3
Years Exp
Azure Sentinel Advanced
8.0/10
1
Years Exp
Threat Intelligence Advanced
7.8/10
2
Years Exp
Sophos Dashboards SentinelOne Firewall Management FortiGate Phishing Malware Analysis UEBA IOC-based Detection Patch Management Coordination ITSM ServiceNow Ticketing Compliance ISO 27001 NIST GDPR Security Reporting Nessus Incident Handling Incident Investigation Root Cause Analysis Log Analysis IBM QRadar LogRhythm Splunk Vulnerability Management EDR Nmap Threat Hunting MITRE ATTCCK Framework Email Security ProofPoint O365 Endpoint Security

Work Experience

Security Analyst

Capgemini

Oct 2022 - May 2023

Provided SOC operations support using IBM QRadar. Monitored security events and performed initial incident analysis. Analyzed security alerts and differentiated false positives from real threats. Maintained detailed incident documentation and SOP adherence. Collaborated with network and endpoint teams for threat containment. Supported SOC operations and security monitoring activities. Conducted vulnerability scans using Qualys and coordinated remediation with IT teams. Ensured log onboarding and health checks for firewalls, servers, databases, and applications. Managed email security controls using Proofpoint. Blocked malicious IPs, domains, and file hashes across firewalls and EDR platforms. Generated vulnerability and SOC reports for senior management. Supported SIEM dashboard troubleshooting and performance optimization.

Senior Security Analyst

Kennametal Shared Services Private Limited

Jun 2023 - Jan 2025

Monitored and analyzed security events using LogRhythm SIEM and Splunk. Investigated incidents including phishing, malware infections, unauthorized access, and policy violations. Performed alert triage, severity classification, and escalation based on business impact. Created and updated incident response playbooks, reducing MTTD and MTTR. Tuned false positives by refining correlation rules, regex, and log parsing. Developed custom AI Engine rules for brute force, lateral movement, and privilege escalation. Integrated threat intelligence feeds and conducted proactive threat hunting. Utilized UEBA to identify insider threats and anomalous user behavior. Prepared detailed investigation reports and presented weekly security summaries to stakeholders.

Senior Security Analyst

EY Global Delivery Services India LLP

Feb 2025 - Present

Working as L2 Security Analyst in SOC using Azure Sentinel, IBM QRadar, and LogRhythm. Monitor, analyze, and investigate real-time security alerts across network, endpoint, cloud, and email environments. Perform end-to-end incident management lifecycle including identification, containment, eradication, RCA, and preventive controls. Conduct vulnerability assessments using Qualys, Nessus, and Nmap; identify critical risks and coordinate remediation. Analyze phishing and spam emails using header, body, and URL analysis; block malicious domains and senders in O365 and Proofpoint. Manage firewall rule updates including IP blacklisting and whitelisting. Tune SIEM correlation rules, dashboards, and alerts to reduce false positives and improve detection accuracy. Map SIEM alerts and detections to the MITRE Attack framework. Prepare daily, weekly, and monthly SOC reports for management and compliance audits. Handle ServiceNow tickets ensuring SLA adherence and proper documentation. Mentor junior analysts and support SOC process improvements. Customized SIEM correlation rules and reports. Integrated MITRE ATT&CK mapping into Azure Sentinel SIEM for structured threat analysis and reporting.

Education

Bachelor of Technology - Sai Spurthi Institute

2014 - 2018 · Afghanistan

Interested in this developer?

Profile Score Breakdown

📷 Photo 10/10
📄 Resume 10/10
💼 Job Title 10/10
✍️ Bio 10/10
🛠️ Skills 20/20
🎓 Education 10/10
⏱️ Experience 5/15
💰 Rate 0/5
🏆 Certs 0/5
Verified 5/5
Total Score 80/100

Profile Overview

Member sinceMay 2025

Availability Details

Visa Status

Citizen

Relocation

Open to Relocation

Skills (39)

SOC Operations SIEM Monitoring Incident Response Azure Sentinel Threat Intelligence Sophos Dashboards SentinelOne Firewall Management FortiGate +29 more