Back to Developers
Sohail

Sohail

Security Analyst

Mumbai 6+ yrs exp 90 ยท Outstanding

About

IT Experience overall 6 years and Security Analyst role with 3 years of experience in enterprise Security Operations Center (SOC) environments supporting 24/7 cybersecurity monitoring and incident response. Strong expertise in SIEM monitoring, detection engineering support, advanced log analysis, endpoint detection and response (EDR), firewall security monitoring, cloud security operations, and vulnerability management. Experienced in handling high-severity (P1/P2) security incidents across network, endpoint, server, email, and cloud environments. Skilled in MITRE ATT&CK mapping, Cyber Kill Chain analysis, root cause analysis, digital evidence collection, and compliance support aligned with NIST and ISO 27001 frameworks.

Skills & Expertise (45)

IBM QRadar Advanced
8.5/10
3
Years Exp
Microsoft Sentinel Advanced
8.5/10
3
Years Exp
LogRhythm Advanced
8.5/10
3
Years Exp
Splunk Advanced
8.5/10
3
Years Exp
McAfee Advanced
8.5/10
3
Years Exp
Symantec Endpoint Protection Advanced
8.5/10
3
Years Exp
CrowdStrike Advanced
8.5/10
3
Years Exp
Nessus Advanced
8.0/10
3
Years Exp
Qualys Advanced
8.0/10
3
Years Exp
AWS Security Advanced
8.0/10
3
Years Exp
CloudTrail Log Analysis Intermediate
7.5/10
3
Years Exp
API Activity Monitoring Intermediate
7.5/10
3
Years Exp
SSH SMTP HTTPS HTTP KPI Reporting DHCP CVSS-Based Risk Prioritization Patch Validation Vulnerability Remediation Tracking SOAR Playbook Support ServiceNow Ticketing Incident Documentation Dashboard Palo Alto Firewall Log Parsing Normalization Correlation Rule Development Use Case Tuning Log Source Onboarding Log Retention Management Process Tree Analysis Registry Monitoring Persistence Mechanism Detection DNS Cisco ASA IDS IPS VPN ACL NAT TCP IP

Work Experience

Security Analyst

Wipro

Jul 2023 - Present

Lead investigation and response of high and critical (P1/P2) cybersecurity incidents across enterprise infrastructure including network, endpoint, server, cloud, and email environments. Perform advanced log analysis and event correlation using Splunk, IBM QRadar, Microsoft Sentinel, and LogRhythm. Detect and investigate security threats including lateral movement, privilege escalation, ransomware indicators, brute force attacks, insider threats, command-and-control (C2) communication, and suspicious outbound traffic. Conduct detailed EDR investigations using CrowdStrike, Symantec, and McAfee by analyzing process trees, command-line execution, registry changes, scheduled tasks, persistence techniques, and abnormal network connections. Map incidents and detection use cases to MITRE ATT&CK techniques to improve monitoring coverage and visibility. Tune SIEM correlation rules to reduce false positives and improve alert accuracy. Perform log onboarding activities including syslog configuration, parsing validation, field extraction, normalization, and event categorization. Monitor SIEM platform performance including log ingestion health, event latency, storage utilization, and data retention compliance. Execute containment actions including endpoint isolation, firewall IP/domain blocking, account lockout, access revocation, and MFA enforcement. Conduct root cause analysis (RCA) to identify attack vector, exploited vulnerability, impacted assets, and business risk exposure. Perform retrospective log analysis after incidents to identify detection gaps and strengthen monitoring rules. Monitored and investigated DLP alerts (data exfiltration, policy violations, sensitive data movement). Analyzed user activity, file transfers, email attachments, and endpoint actions for data leakage risks. Investigate phishing campaigns including email header analysis, spoofing validation, URL detonation, and attachment sandboxing. Analyze authentication logs to detect password spraying, credential stuffing, abnormal login patterns, and suspicious geo-location activity. Support vulnerability remediation validation by reviewing Nessus and Qualys scan findings and verifying patch implementation. Collaborate with VAPT teams to validate exploitability and remediation closure. Led shift handovers, incident prioritization, workload distribution, and SLA governance. Document incident findings in ServiceNow ensuring SLA compliance and audit traceability. Worked with Microsoft Sentinel & Logic Apps to support alert automation and response workflows. Assisted in developing playbooks for automated actions such as alert enrichment, ticket creation, and notification triggers. Coordinated with OEM vendors (Microsoft, CrowdStrike, SIEM providers) for issue resolution, threat intelligence, and advanced investigations. Participated in governance meetings, incident review boards, and lessons learned sessions. Provide SOC operational evidence aligned with ISO 27001 and NIST compliance audits.

IT Desktop Support Engineer

Cadential Technologies Private Limited

May 2020 - Jun 2023

Installed, configured, and maintained servers, desktops, laptops, and mobile devices. Managed user accounts, groups, and permissions using Active Directory. Provided technical support for hardware, software, and network-related issues. Monitored and maintained network devices such as routers, switches, and firewalls. Ensured regular system backups and tested disaster recovery plans. Applied software updates, patches, and security fixes to all client systems. Supported Microsoft 365 services including Exchange Online, Teams, and SharePoint. Implemented antivirus and endpoint security solutions to protect client data. Managed virtualization platforms like VMware and Hyper-V for efficient resource use. Created and updated IT documentation, including network diagrams and SOPs. Supported VoIP phone systems and business communication tools. Coordinated with vendors for hardware/software procurement and technical support. Provided remote and on-site client support to ensure minimal downtime.

Education

Bachelor of Technology - Anwar Ul-Uloom College of Engineering, JNTU University

- ยท Afghanistan

Certifications

No certifications added yet

Interested in this developer?

Profile Score Breakdown

๐Ÿ“ท Photo 10/10
๐Ÿ“„ Resume 10/10
๐Ÿ’ผ Job Title 10/10
โœ๏ธ Bio 10/10
๐Ÿ› ๏ธ Skills 20/20
๐ŸŽ“ Education 10/10
โฑ๏ธ Experience 15/15
๐Ÿ’ฐ Rate 0/5
๐Ÿ† Certs 0/5
โœ… Verified 5/5
Total Score 90/100

Profile Overview

Member sinceJul 2026