Back to Developers
Gopal SB

Gopal SB

SOC Analyst & Incident Responder

Pune, India 3+ yrs exp 87 ยท Excellent

About

SOC Analyst with close to four years of experience spanning banking, product, and managed-security environments. Most days are spent triaging QRadar and Sentinel alerts, chasing down IOCs, and writing the AQL and KQL queries that turn a vague alert into a clear answer. Comfortable taking a phishing email or a flagged endpoint from first look through to closure, and has built and tuned SIEM use cases whenever the existing rules weren't catching what they should. Background also covers malware analysis, vulnerability scanning, and the basics of cloud security across AWS and Azure (SC-900 and AZ-900 certified, AZ-104 in progress).

Skills & Expertise (46)

IBM QRadar Advanced
8.0/10
3.5
Years Exp
Splunk Intermediate
7.5/10
2
Years Exp
IOC Analysis Intermediate
7.0/10
3.5
Years Exp
WIRESHARK Intermediate
7.0/10
3.5
Years Exp
MITRE ATT&CK Intermediate
7.0/10
3.5
Years Exp
Phishing Investigation Intermediate
7.0/10
3.5
Years Exp
Threat Hunting Intermediate
7.0/10
3.5
Years Exp
Alert Triage Intermediate
7.0/10
3.5
Years Exp
Microsoft Defender for Endpoint Intermediate
7.0/10
1
Years Exp
Palo Alto Cortex XSOAR Intermediate
7.0/10
1
Years Exp
Elastic SIEM Intermediate
7.0/10
1
Years Exp
IBM Qradar SOAR Intermediate
7.0/10
1
Years Exp
KQL Intermediate
7.0/10
1
Years Exp
CrowdStrike Falcon Intermediate
6.5/10
1
Years Exp
Microsoft Sentinel Intermediate
6.5/10
1
Years Exp
Cortex XDR Intermediate
6.5/10
1
Years Exp
BlueCoat Intermediate
6.0/10
2
Years Exp
Zscaler Intermediate
6.0/10
2
Years Exp
Hydra Intermediate
6.0/10
2
Years Exp
Gobuster Intermediate
6.0/10
2
Years Exp
PowerShell Scripting Intermediate
6.0/10
2
Years Exp
Metasploit Intermediate
6.0/10
2
Years Exp
Kali Linux Intermediate
6.0/10
2
Years Exp
Burp Suite Intermediate
6.0/10
2
Years Exp
IBM X-Force Intermediate
6.0/10
2
Years Exp
Anyrun Intermediate
6.0/10
2
Years Exp
Recorded Future Intermediate
6.0/10
2
Years Exp
IPvoid Intermediate
6.0/10
2
Years Exp
AbuseIPDB Intermediate
6.0/10
2
Years Exp
VirusTotal Intermediate
6.0/10
2
Years Exp
GCP Intermediate
6.0/10
2
Years Exp
Azure Intermediate
6.0/10
2
Years Exp
AWS Intermediate
6.0/10
2
Years Exp
Nmap Intermediate
6.0/10
2
Years Exp
Qualys Intermediate
6.0/10
2
Years Exp
Nessus Intermediate
6.0/10
2
Years Exp
IPS Intermediate
6.0/10
2
Years Exp
Imperva Intermediate
6.0/10
2
Years Exp
F5 Intermediate
6.0/10
2
Years Exp
Akamai Intermediate
6.0/10
2
Years Exp
Tcpdump Intermediate
6.0/10
2
Years Exp
Dynamic Malware analysis Intermediate
6.0/10
2
Years Exp
Static Malware Analysis Intermediate
6.0/10
2
Years Exp
Sophos Intermediate
6.0/10
1
Years Exp
SPL Intermediate
6.0/10
1
Years Exp
AQL Intermediate
6.0/10
1
Years Exp

Work Experience

SOC Analyst L1

Qodequay Technologies Private Limited

Nov 2025 - Apr 2026

Worked QRadar, Defender for Endpoint, and Cortex XDR alerts day to day, separating genuine threats from noise. Dug into flagged accounts and endpoints to confirm or rule out compromise, malware, or insider activity, documenting the reasoning either way. Pulled apart IOC sets (IPs, domains, URLs, file hashes) to figure out how far an incident actually spread. Sandboxed suspicious attachments and links from reported phishing emails, cross-checking against threat intel feeds before closing tickets. Kept an eye on QRadar's log ingestion and correlation rules so offenses were generating correctly, not silently failing.

SOC Analyst

CyberNX Technologies Private Limited

Apr 2025 - Sep 2025

Ran point on Elastic SIEM monitoring, writing KQL and Lucene queries to chase down anomalies as they came up. Handled a steady mix of brute-force attempts, phishing, malware, and lateral-movement alerts, writing up root cause and remediation for each. Worked closely with SecOps, DevOps, and IT to get vulnerabilities patched and controls actually implemented, not just flagged. Used Elastic, Wireshark, and Nessus together for log review, hunting, and periodic vulnerability checks. Isolated affected systems during live incidents and pushed remediation steps through to the right teams.

Security Consultant (Banking Project)

Deloitte India

Jul 2022 - Feb 2025

Owned QRadar event and flow monitoring and offense analysis for a large banking client over more than two years. Built out SOAR playbooks in Palo Alto to cut down manual steps in incident response. Ran Qualys vulnerability scans and stayed on remediation tracking until issues actually closed out. Pulled logs from WAFs (Akamai, F5, Imperva), TippingPoint IPS, Azure Sentinel, Zscaler, Bluecoat, AWS, and SEPM/SEDR to piece together incidents spanning multiple tools. Proposed new detection use cases mapped to MITRE ATT&CK where existing coverage had gaps. Worked with L3 and IR teams on root cause analysis and incident sign-off; tracked EPS load and tuned SIEM performance, then reported findings in QBR and MBR sessions.

Education

B.E. in Mechanical Engineering - Jain Institute of Technology

2015 - 2019 ยท Afghanistan

Certifications

No certifications added yet

Interested in this developer?

Profile Score Breakdown

๐Ÿ“ท Photo 10/10
๐Ÿ“„ Resume 10/10
๐Ÿ’ผ Job Title 10/10
โœ๏ธ Bio 10/10
๐Ÿ› ๏ธ Skills 20/20
๐ŸŽ“ Education 10/10
โฑ๏ธ Experience 12/15
๐Ÿ’ฐ Rate 0/5
๐Ÿ† Certs 0/5
โœ… Verified 5/5
Total Score 87/100

Profile Overview

Member sinceJul 2026