sivavenkatasainalla
Cybersecurity Engineer
About
Cybersecurity Engineer with 4+ years of experience securing enterprise environments through proactive threat detection, incident response, and endpoint security operations. Hands-on expertise in Microsoft Sentinel and Splunk SIEM for KQL/SPL-based detection engineering, alert triage, and security monitoring across endpoint, network, and identity sources. Skilled in endpoint protection using Microsoft Defender for Endpoint (MDE) and Microsoft Defender XDR, with experience performing endpoint isolation, IOC blocking, and threat hunting to contain malware and ransomware incidents. Strong background in network security โ managing Cloudflare WAF policies and to defend against OWASP Top 10 attacks, bot traffic, and application-layer threats. Experienced in cloud security using Microsoft Defender for Cloud to investigate Azure workload alerts and misconfigurations, and in identity access management using Azure Entra ID, RBAC, Conditional Access, and MFA to secure authentication and access workflows. Proficient in vulnerability management with Nessus and Qualys, prioritizing remediation by CVSS score and business impact. Applies the MITRE ATT&CK framework and conducts root cause analysis to continuously strengthen security posture and incident response maturity.
Skills & Expertise (19)
Work Experience
Cybersecurity Engineer
BNP Paribas
Jul 2022 - Present
Implemented threat detection rules in Microsoft Sentinel using built-in analytics and custom KQL-based detection rules. Tuned analytics rules, configured alert suppression, and managed watchlists to improve detection accuracy and reduce false positives. Monitored and triaged security alerts in Splunk SIEM as part of daily SOC operations, investigating incidents across endpoint, network, identity, and cloud data sources. Built and optimized Splunk SPL (Search Processing Language) queries to investigate security incidents, perform log analysis, and support threat hunting activities. Built Splunk dashboards consolidating security telemetry from firewalls, endpoints, and identity sources for real-time SOC monitoring and compliance reporting. Performed real-time monitoring and triage of alerts from Microsoft Sentinel and investigated phishing, malware, and credential theft incidents. Monitored endpoint threats using Microsoft Defender for Endpoint (MDE) to detect malware, ransomware, fileless attacks, and suspicious process activity across enterprise endpoints. Performed endpoint isolation, file quarantine, and IOC blocking during active security incidents to contain threats and prevent lateral movement. Conducted KQL-based advanced hunting in Microsoft Defender XDR to proactively search for indicators of compromise and attacker behavior across endpoints. Investigated and triaged Defender XDR incidents, correlating signals across endpoints, identity, and email to build comprehensive attack timelines. Assisted in managing and configuring Cloudflare WAF policies, including firewall rules, IP reputation filtering, rate limiting, and bot mitigation controls. Developed and deployed WAF protections against OWASP Top 10 threats such as SQL Injection (SQLi), Cross-Site Scripting (XSS), command injection, and application-layer attacks. Monitored and analyzed network and web application traffic using firewall logs, Cloudflare analytics, and security monitoring tools to detect malicious activity. Monitored and investigated phishing alerts, triaged suspicious emails, and escalated confirmed threats using Abnormal Security. Investigated phishing campaigns, malicious URLs, and email-based threats as part of SOC operations. Performed real-time investigation of phishing and credential theft incidents using Microsoft security solutions. Performed vulnerability assessments and identified security weaknesses across servers, endpoints, and network devices. Analyzed and prioritized vulnerabilities based on CVSS scores, asset criticality, and business impact to support remediation efforts. Investigated Microsoft Defender for Cloud security alerts across Azure workloads, including suspicious activities, exposed resources, malware detections, and security misconfigurations. Monitored Azure security posture and cloud threats using Microsoft Defender for Cloud and Azure security services. Investigated identity-related incidents involving credential theft and suspicious authentication activities. Supported access control and security monitoring aligned with RBAC, Conditional Access, and MFA policies. Applied MITRE ATT&CK techniques to classify adversary tactics, techniques, and procedures (TTPs). Conducted root cause analysis (RCA) for security incidents and documented findings, lessons learned, and remediation actions.
Education
MBA - JNTU- Kakinada
- ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (19)
Click a skill to find developers with the same skill