Back to Developers
Nikhitha Tenali

Nikhitha Tenali

SOC Analyst

Hyderabad, India 3+ yrs exp 86 ยท Excellent

About

SOC Analyst with 3 years of experience in a 24x7 multi-client Security Operations Center supporting enterprise environments across transportation, aviation, logistics, engineering, and energy sectors. Experienced in security monitoring, SIEM investigation, incident triage, log correlation, alert tuning, rule validation, and detection engineering. Independently designed, built, and implemented 15+ detection use cases in Cortex XSIAM using XQL, strengthening detection coverage and investigation capabilities. Performs L2-level investigation and detection activities beyond standard L1 monitoring responsibilities, including historical log analysis, user behavior analysis, threat validation, root-cause investigation, and incident scoping. Experienced with IBM QRadar, Cortex XSIAM, ManageEngine Log360, Microsoft Defender, Microsoft Sentinel, and security investigation tools. Strong client-facing experience preparing and presenting weekly and monthly security reports. Recognized as Star of the Month at Tata Consultancy Services for fast learning, initiative, and proactive problem-solving.

Skills & Expertise (27)

Cortex Xsiam Advanced
8.5/10
3
Years Exp
Security Alert Triage Advanced
8.0/10
3
Years Exp
Cyber Kill Chain Advanced
8.0/10
3
Years Exp
MITRE ATT&CK Advanced
8.0/10
3
Years Exp
Root Cause Analysis Advanced
8.0/10
3
Years Exp
User Behavior Analysis Advanced
8.0/10
3
Years Exp
Incident Investigation Advanced
8.0/10
3
Years Exp
log correlation Advanced
8.0/10
3
Years Exp
False Positive Analysis Advanced
8.0/10
3
Years Exp
Alert Tuning Advanced
8.0/10
3
Years Exp
IBM QRadar Intermediate
7.8/10
3
Years Exp
Microsoft Defender EDR Intermediate
7.0/10
3
Years Exp
Knowledge Base Documentation Intermediate
7.0/10
3
Years Exp
Security Metrics Intermediate
7.0/10
3
Years Exp
Microsoft Sentinel Intermediate
7.0/10
3
Years Exp
IOC Analysis Intermediate
7.0/10
3
Years Exp
KQL Intermediate
7.0/10
3
Years Exp
XDR Intermediate
7.0/10
3
Years Exp
VirusTotal Intermediate
6.5/10
3
Years Exp
ManageEngine Log360 Intermediate
6.5/10
3
Years Exp
SPL Intermediate
6.5/10
3
Years Exp
Splunk Intermediate
6.0/10
3
Years Exp
AbuseIPDB Intermediate
6.0/10
3
Years Exp
IPvoid Intermediate
6.0/10
3
Years Exp
PhishTool Intermediate
6.0/10
3
Years Exp
ServiceNow Intermediate
6.0/10
3
Years Exp
Qualys Intermediate
5.5/10
3
Years Exp

Work Experience

SOC Analyst

Tata Consultancy Services (TCS)

Aug 2023 - Present

Perform security monitoring, alert triage, and incident investigation in a 24x7 multi-client Security Operations Center supporting enterprise clients across transportation, aviation, logistics, engineering, and energy sectors. Perform L2-level investigation and detection engineering activities beyond standard L1 monitoring responsibilities, including advanced alert investigation, log correlation, historical event analysis, user behavior analysis, threat validation, and root-cause investigation. Independently designed, developed, and implemented 15+ SIEM detection use cases in Cortex XSIAM using XQL, improving detection coverage and enabling more effective identification and investigation of suspicious security activity. Develop and refine detection logic by performing alert tuning, rule validation, and false-positive analysis, improving alert quality and reducing unnecessary investigation effort. Investigate and triage security alerts across IBM QRadar, Cortex XSIAM, ManageEngine Log360, and Microsoft Defender, correlating events across SIEM and endpoint platforms to validate threats, assess impact, determine root cause, and escalate confirmed incidents according to client procedures. Analyze historical log data and user behavior patterns to establish event timelines, validate suspicious activity, determine attack scope, and support incident-response decisions. Use threat intelligence and OSINT platforms including VirusTotal, AbuseIPDB, IPVoid, and PhishTool to enrich investigations and assess indicators of compromise. Prepare and present weekly and monthly security reports directly to client stakeholders, communicating incident trends, key findings, risk exposure, recurring alert patterns, and remediation status to technical and non-technical audiences. Create and maintain SOC knowledge-base documentation, alert-reference matrices, investigation guidance, and standardized triage workflows to improve operational consistency and accelerate analyst onboarding. Conduct knowledge-transfer sessions for new team members covering SIEM navigation, alert investigation, triage procedures, escalation workflows, and SOC operational processes.

Education

B.Tech โ€“ Computer Science & Engineering - Rajiv Gandhi University of Knowledge Technologies (RGUKT-IIIT)

2019 - 2023 ยท Afghanistan

Certifications

No certifications added yet

Interested in this developer?

Profile Score Breakdown

๐Ÿ“ท Photo 10/10
๐Ÿ“„ Resume 10/10
๐Ÿ’ผ Job Title 10/10
โœ๏ธ Bio 10/10
๐Ÿ› ๏ธ Skills 20/20
๐ŸŽ“ Education 10/10
โฑ๏ธ Experience 11/15
๐Ÿ’ฐ Rate 0/5
๐Ÿ† Certs 0/5
โœ… Verified 5/5
Total Score 86/100

Profile Overview

Member sinceSep 2026