Sathiyamoorthi Selvaraj
Senior Manager – SOC
About
Cybersecurity leader with 14+ years of progressive experience spanning SOC operations, security engineering, threat hunting, incident response, and malware analysis. Currently Senior Manager – SOC at Tata Communications, leading a 24/7 SOC team and owning the full security engineering stack (SIEM, EDR/EPP, DLP, CASB). Skilled in building SOAR-driven automation, aligning detections to the MITRE ATT&CK framework, and translating operational risk into executive-ready reporting for CISOs and senior leadership. Track record of tightening detection and response cycles, strengthening compliance posture, and developing high-performing security teams. Immediately available to join.
Skills & Expertise
No skills listed yet
Work Experience
Senior Manager – SOC (Security Engineering)
Tata Communications
Dec 2025 - Present
Own the Security Engineering function end-to-end, administering SIEM, EDR/EPP, DLP, and CASB platforms across the enterprise. Integrate all assets and endpoints into SIEM and EDR/EPP to deliver comprehensive threat visibility and protection. Deploy and fine-tune CASB/DLP policies across all communication channels to prevent data exfiltration. Drive SOAR automation initiatives that reduce manual analyst workload on repetitive triage tasks. Build executive-ready dashboards and customized reporting for the CISO and senior management. Review and validate SIEM use-case effectiveness; deploy new detection rules mapped to the MITRE ATT&CK framework. Manage license renewals and long-term capacity planning across the security toolset. Ensure regulatory and compliance requirements are met through strategic tool deployment and governance.
Senior Manager – SOC (24/7 Operations)
Tata Communications
Sep 2021 - Dec 2025
Led a 24/7 SOC operations team responsible for monitoring, triaging, and escalating security incidents; reported directly to the CISO. Managed EDR deployment across all endpoints, continuously improving detections through policy tuning and IOA/IOC analysis. Defined and tracked SOC KPIs (including detection and response metrics) to measure team effectiveness and align with organizational security goals. Conducted end-to-end analysis of security incidents using the Cyber Kill Chain methodology. Developed proactive threat-hunting methods leveraging the MITRE ATT&CK framework and emerging TTPs. Oversaw preparation for security audits, ensuring the SOC demonstrated adherence to best practices. Owned major security incidents end-to-end, coordinating stakeholder communication through to closure. Authored and implemented security policies derived from post-incident learnings. Applied reverse engineering, disk forensics, and memory forensics techniques to major investigations.
SOC Analyst
Infosys
Jun 2020 - Sep 2021
Continued a client engagement transitioned from Cognizant on client recommendation, retaining the same project scope and technology stack. Monitored and responded to security incidents while maintaining consistent SLAs and service quality.
SOC Analyst
Cognizant Technology Solutions
Feb 2018 - Jun 2020
Served as primary handler for all security incidents, working closely with vulnerability and compliance teams. Monitored security controls via SIEM (Splunk); worked across email analysis, IDS/IPS, endpoint AV, NGAV, WAF, and email gateway. Performed static and dynamic malware analysis using IDA Pro, X64dbg, and HexEdit, specializing in APT attack analysis. Conducted OSINT investigations to profile threat actors and identify root causes. Maintained AWS security posture using CloudTrail, CloudWatch, and GuardDuty to detect cloud anomalies. Handled spam, phishing, and scam email incidents, delivering root-cause analysis for all security events. Proactively monitored and patched zero-day vulnerabilities across the environment.
Antivirus / Endpoint Security Specialist (L3)
Hewlett Packard Enterprises
Jun 2016 - Feb 2018
Managed antivirus across all workstations and servers, handling incidents and changes on McAfee ePO 5.3.1, Symantec EP 11, and Trend Micro Deep Security / OfficeScan (L3). Supported (L3) McAfee Agent, VSE, HIPS, and Solid Core; led AV console and client console upgrades. Performed monthly vulnerability assessments using EMET and Qualys VM, plus monthly server audits. Authored technical troubleshooting documentation and zero-day infection advisories ahead of network impact. Produced an in-depth technical analysis of the Zepto ransomware outbreak.
Technical Specialist
Mindtree Ltd.
Apr 2014 - May 2016
Managed antivirus across all workstations and servers, handling McAfee, Symantec, and Defender AV incidents and changes. Collected and analyzed zero-day infections using multiple tools; strengthened endpoint protection coverage. Hands-on with McAfee ePO 4.6.x, Symantec EP 11, Microsoft Forefront, and Microsoft ISA 2006 / Threat Management Gateway. Researched emerging malware families including Emotet, Dyzap, and Cryptowall 3.0, and briefed the team on infection trends.
System Engineer
iOPEX Technologies
Mar 2011 - Mar 2014
Provided remote troubleshooting for PC and malware/rootkit issues, including manual removal of advanced rootkits. Resolved file permission, driver, Windows update, login, and registry-level issues, plus antivirus conflicts. Delivered hands-on support for McAfee and Norton Antivirus at the workstation level.
Education
B.E. – Information Technology - Mookambigai College of Engineering
2007 - 2010 · Afghanistan
Diploma – Information Technology - R.V.S. Polytechnic College
2005 - 2007 · Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Citizen
Relocation
Depends on Offer