About
SOC Analyst with close to four years of experience spanning banking, product, and managed-security environments. Most days are spent triaging QRadar and Sentinel alerts, chasing down IOCs, and writing the AQL and KQL queries that turn a vague alert into a clear answer. Comfortable taking a phishing email or a flagged endpoint from first look through to closure, and has built and tuned SIEM use cases whenever the existing rules weren't catching what they should. Background also covers malware analysis, vulnerability scanning, and the basics of cloud security across AWS and Azure (SC-900 and AZ-900 certified, AZ-104 in progress).
Skills & Expertise (46)
Work Experience
SOC Analyst L1
Qodequay Technologies Private Limited
Nov 2025 - Apr 2026
Worked QRadar, Defender for Endpoint, and Cortex XDR alerts day to day, separating genuine threats from noise. Dug into flagged accounts and endpoints to confirm or rule out compromise, malware, or insider activity, documenting the reasoning either way. Pulled apart IOC sets (IPs, domains, URLs, file hashes) to figure out how far an incident actually spread. Sandboxed suspicious attachments and links from reported phishing emails, cross-checking against threat intel feeds before closing tickets. Kept an eye on QRadar's log ingestion and correlation rules so offenses were generating correctly, not silently failing.
SOC Analyst
CyberNX Technologies Private Limited
Apr 2025 - Sep 2025
Ran point on Elastic SIEM monitoring, writing KQL and Lucene queries to chase down anomalies as they came up. Handled a steady mix of brute-force attempts, phishing, malware, and lateral-movement alerts, writing up root cause and remediation for each. Worked closely with SecOps, DevOps, and IT to get vulnerabilities patched and controls actually implemented, not just flagged. Used Elastic, Wireshark, and Nessus together for log review, hunting, and periodic vulnerability checks. Isolated affected systems during live incidents and pushed remediation steps through to the right teams.
Security Consultant (Banking Project)
Deloitte India
Jul 2022 - Feb 2025
Owned QRadar event and flow monitoring and offense analysis for a large banking client over more than two years. Built out SOAR playbooks in Palo Alto to cut down manual steps in incident response. Ran Qualys vulnerability scans and stayed on remediation tracking until issues actually closed out. Pulled logs from WAFs (Akamai, F5, Imperva), TippingPoint IPS, Azure Sentinel, Zscaler, Bluecoat, AWS, and SEPM/SEDR to piece together incidents spanning multiple tools. Proposed new detection use cases mapped to MITRE ATT&CK where existing coverage had gaps. Worked with L3 and IR teams on root cause analysis and incident sign-off; tracked EPS load and tuned SIEM performance, then reported findings in QBR and MBR sessions.
Education
B.E. in Mechanical Engineering - Jain Institute of Technology
2015 - 2019 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (46)
Click a skill to find developers with the same skill