About
SOC Analyst with 3 years of experience in a 24x7 multi-client Security Operations Center supporting enterprise environments across transportation, aviation, logistics, engineering, and energy sectors. Experienced in security monitoring, SIEM investigation, incident triage, log correlation, alert tuning, rule validation, and detection engineering. Independently designed, built, and implemented 15+ detection use cases in Cortex XSIAM using XQL, strengthening detection coverage and investigation capabilities. Performs L2-level investigation and detection activities beyond standard L1 monitoring responsibilities, including historical log analysis, user behavior analysis, threat validation, root-cause investigation, and incident scoping. Experienced with IBM QRadar, Cortex XSIAM, ManageEngine Log360, Microsoft Defender, Microsoft Sentinel, and security investigation tools. Strong client-facing experience preparing and presenting weekly and monthly security reports. Recognized as Star of the Month at Tata Consultancy Services for fast learning, initiative, and proactive problem-solving.
Skills & Expertise (27)
Work Experience
SOC Analyst
Tata Consultancy Services (TCS)
Aug 2023 - Present
Perform security monitoring, alert triage, and incident investigation in a 24x7 multi-client Security Operations Center supporting enterprise clients across transportation, aviation, logistics, engineering, and energy sectors. Perform L2-level investigation and detection engineering activities beyond standard L1 monitoring responsibilities, including advanced alert investigation, log correlation, historical event analysis, user behavior analysis, threat validation, and root-cause investigation. Independently designed, developed, and implemented 15+ SIEM detection use cases in Cortex XSIAM using XQL, improving detection coverage and enabling more effective identification and investigation of suspicious security activity. Develop and refine detection logic by performing alert tuning, rule validation, and false-positive analysis, improving alert quality and reducing unnecessary investigation effort. Investigate and triage security alerts across IBM QRadar, Cortex XSIAM, ManageEngine Log360, and Microsoft Defender, correlating events across SIEM and endpoint platforms to validate threats, assess impact, determine root cause, and escalate confirmed incidents according to client procedures. Analyze historical log data and user behavior patterns to establish event timelines, validate suspicious activity, determine attack scope, and support incident-response decisions. Use threat intelligence and OSINT platforms including VirusTotal, AbuseIPDB, IPVoid, and PhishTool to enrich investigations and assess indicators of compromise. Prepare and present weekly and monthly security reports directly to client stakeholders, communicating incident trends, key findings, risk exposure, recurring alert patterns, and remediation status to technical and non-technical audiences. Create and maintain SOC knowledge-base documentation, alert-reference matrices, investigation guidance, and standardized triage workflows to improve operational consistency and accelerate analyst onboarding. Conduct knowledge-transfer sessions for new team members covering SIEM navigation, alert investigation, triage procedures, escalation workflows, and SOC operational processes.
Education
B.Tech โ Computer Science & Engineering - Rajiv Gandhi University of Knowledge Technologies (RGUKT-IIIT)
2019 - 2023 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (27)
Click a skill to find developers with the same skill