sandeep
Cybersecurity professional
About
Cybersecurity professional with 4.4 years of experience in security engineering. Proven ability to assess business systems for risk identification and implement effective security measures. Developed and executed strategies that enhance compliance and bolster operational resilience.
Skills & Expertise (23)
Work Experience
Security Analyst
LTM
Mar 2022 - Present
Hands-on experience in analysing phishing emails and malware emails, performing soft deletes and hard deletes of malicious emails from the email cluster, and adding indicators to the tenant allow list, block list, and based on analysing the IOCs. Splunk SIEM monitoring includes licence monitoring, indexer storage volume monitoring, Splunk application daily health-check monitoring, and event and incident monitoring. Experience in AIR (Automated Investigations and Remediation) policies and their implementation. Experienced in managing DLP policies and deploying Purview agents on servers and domain controllers. Experienced in creating conditional access policies and managing licences in Azure Entra ID. Performed folder exclusion policies, device-based policies, and tags in Defender for Endpoint. Good hands-on experience in creating custom detection rules using the KQL language and fine-tuning use cases to reduce false positives in Defender 365 and Azure Sentinel. Configure and manage dashboards, notebooks, data connectors, and playbooks in Azure Sentinel. Hunt for security threats using Azure Sentinel. Good knowledge of analysing different malicious executables and documents. Good understanding of Azure Active Directory, Azure MFA, and conditional access. Experience in supporting, fine-tuning, and troubleshooting correlation searches in Splunk SIEM. Good hands-on experience in creating the SOPs, playbooks, and runbooks using Splunk and Defender, as well as hands-on experience in creating and managing the endpoint health check reports and vulnerability reports to reduce the exposure score. Good hands-on experience in providing KT sessions, training, and assigning tasks to juniors. Experience in creating and maintaining the daily, weekly, and monthly reports of device health status by using Defender ATP. Knowledge of Group Policy Objects, Active Directory security and compliance configurations, and migrating to the Intune administrator console. Experience in working on host isolation and advanced threat analysis using EDR, Microsoft Defender ATP, and other tools. Experience in creating group policies and initiating remote wipe-outs on end devices by using the Intune administrator console. Implemented conditional access policies and integrated Intune with Azure Active Directory for enhanced security, and user authentication.
Education
Master of Science in Mechanical Engineering - Sapienza University of Rome
- 2022 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (23)
Click a skill to find developers with the same skill