Back to Developers
Vidya T

Vidya T

Threat Hunter | SOC Analyst L2

Bengaluru, India 4+ yrs exp 90 · Outstanding

About

Threat Hunter and SOC Analyst (L2) with 5+ years of experience proactively identifying, investigating, and mitigating advanced threats across enterprise, cloud, and hybrid environments. Skilled in hypothesis-driven threat hunting mapped to the MITRE ATT&CK framework, using Microsoft Sentinel, Hunters SIEM, Splunk, Defender XDR, and CrowdStrike Falcon to uncover IOCs, IOAs, and hidden attacker behavior. Experienced investigating APTs, ransomware, insider threats, and phishing/BEC campaigns, performing malware analysis, root cause analysis, and cross-team incident response. Skilled in vulnerability management and patch management, including scanning, risk-based prioritization, and remediation tracking to reduce enterprise attack surface. Proven track record reducing false positives, improving detection fidelity, and mentoring L1 analysts in fast-paced SOC operations.

Skills & Expertise (62)

MITRE ATT&CK framework Advanced
9.0/10
5
Years Exp
Behavioral Analytics Advanced
8.5/10
5
Years Exp
Microsoft Sentinel Advanced
8.5/10
5
Years Exp
Splunk Advanced
8.5/10
5
Years Exp
Post-Incident Reviews Advanced
8.0/10
5
Years Exp
Incident Response Playbooks Advanced
8.0/10
5
Years Exp
Vulnerability Scanning Advanced
8.0/10
5
Years Exp
Root Cause Analysis Advanced
8.0/10
5
Years Exp
Malware Analysis Advanced
8.0/10
5
Years Exp
Crowdstrike Falcon EDR Advanced
8.0/10
5
Years Exp
Python Intermediate
7.5/10
5
Years Exp
PowerShell Intermediate
7.5/10
5
Years Exp
KQL KnowBe4 SOPs KnowBe4 phishing simulation WIRESHARK Tcpdump Suricata Snort Zeek Nmap Yara Rules Sysmon Volatility Burp Suite Mimecast SPL ISO 27001 ProofPoint Cisco Umbrella Windows Server Active Directory LINUX Nessus Postman AlienVault OTX Ioa analysis UEBA Anomaly Detection Splunk Phantom IBM QRadar Elastic SIEM Azure Sentinel Microsoft Defender XDR Microsoft Defender for Endpoint Phishing Investigation VirusTotal AbuseIPDB SLA tracking patch management Remediation Tracking Orca Security Qualys Microsoft Intune Microsoft Azure Entra ID Microsoft 365 IOC SOC 2 NIST CSF ServiceNow

Work Experience

SOC Analyst – Level 2

Coforge

Dec 2023 - Present

Led proactive, hypothesis-driven threat hunting operations using behavioral analytics, IOC matching, UEBA, and anomaly detection; identified 10+ advanced persistent threats before escalation. Investigated advanced persistent threats, ransomware, phishing, business email compromise (BEC), malware infections, and insider threat incidents; coordinated containment and eradication with IT and IR teams. Analyzed multi-source security telemetry in Hunters SIEM, correlating logs across endpoint, identity, and cloud to surface suspicious behaviors, lateral movement, and attack patterns. Monitored and triaged security alerts using Microsoft Sentinel and Defender XDR across endpoints, Azure workloads, identity, and SaaS applications; maintained 98%+ SLA adherence. Conducted endpoint investigations and malware analysis using CrowdStrike Falcon EDR, including process tree review and containment of compromised hosts. Performed root cause analysis (RCA) and post-incident reviews for confirmed security events, documenting findings and remediation recommendations. Enriched alerts with IOC reputation, threat actor TTPs, and emerging attack trends using Cyble Threat Intelligence, improving alert fidelity and response speed. Correlated SIEM, EDR, vulnerability, and threat intelligence data to reduce false positives by 30%, sharpening focus on high-priority incidents. Managed vulnerability management and patching lifecycle using Orca Security, running scans, assessing exploitability and business impact, and coordinating remediation and patch deployment with IT teams; reduced open critical findings by 35%. Performed SIEM log correlation between Sentinel, Entra ID, and Defender to identify unauthorized logins, privilege escalation, and lateral movement paths. Worked with Intune policies to verify endpoint compliance, enforce patch deployment, and isolate high-risk devices during active incidents, significantly reducing dwell time. Conducted periodic security audits aligned with ISO 27001 and SOC 2 frameworks in collaboration with IT and compliance teams. Mentored L1 analysts on alert prioritization, escalation procedures, SOAR playbooks, and IOC triage methodologies. Authored and maintained incident response playbooks, SOPs, and knowledge base articles for recurring event patterns. Designed and operationalized custom threat hunting queries (KQL, SPL) in Sentinel and Splunk to surface living-off-the-land binaries, fileless malware, and C2 beaconing patterns undetected by existing correlation rules, expanding detection coverage across the MITRE ATT&CK matrix. Built a structured, intelligence-led threat hunting cadence — combining hypothesis generation, adversary emulation, and ATT&CK-based gap analysis — to proactively uncover stealthy persistence and privilege escalation techniques ahead of automated detection. Owned end-to-end patch management governance for critical and zero-day vulnerabilities, driving emergency patch cycles across 1,000+ endpoints via Orca Security and Intune and reporting SLA compliance metrics to leadership. Partnered with IT infrastructure teams to design a risk-based patch prioritization framework (CVSS score, exploit availability, asset criticality), cutting mean-time-to-patch for critical CVEs and reducing recurring audit findings.

SOC Analyst – Level 1

Coforge

Aug 2021 - Nov 2023

Conducted threat hunting to detect credential misuse, privilege escalation, and persistence techniques mapped to MITRE ATT&CK tactics and techniques. Assisted senior analysts in building baseline behavioral profiles for critical assets, enabling faster identification of anomalous activity during proactive threat hunts. Performed 24x7 real-time monitoring and triage of security alerts and logs using Splunk and Splunk Phantom SOAR across a multi-client environment. Investigated phishing emails, user lockouts, endpoint detections, and suspicious network activity using Microsoft Defender for Endpoint and CrowdStrike Falcon. Verified alert legitimacy through multi-source reputation checks using VirusTotal, AbuseIPDB, and AlienVault OTX before escalating confirmed incidents. Validated and tuned SIEM detection rules and correlation searches to reduce false positives and improve detection efficiency. Supported vulnerability scanning and patch compliance checks, flagging unpatched and missing critical updates on endpoints for remediation. Tracked patch deployment SLAs across Windows and third-party applications, coordinating with IT teams to close out overdue critical and high-severity patches. Escalated validated security incidents to L2/L3 teams following established SOPs and incident classification guidelines. Documented security incidents, investigation timelines, and IOCs; maintained knowledge base of recurring event patterns. Supported threat intelligence correlation, IOC enrichment, and weekly threat landscape reporting for security leadership. Executed and managed phishing simulation campaigns via KnowBe4; delivered security awareness metrics and training effectiveness reports. Monitored SIEM dashboards and generated daily/weekly security operations reports highlighting trends and open incidents.

Education

MBA - PSCMR College of Engineering

- 2019 · Afghanistan

Certifications

No certifications added yet

Interested in this developer?

Profile Score Breakdown

📷 Photo 10/10
📄 Resume 10/10
💼 Job Title 10/10
✍️ Bio 10/10
🛠️ Skills 20/20
🎓 Education 10/10
⏱️ Experience 15/15
💰 Rate 0/5
🏆 Certs 0/5
Verified 5/5
Total Score 90/100

Profile Overview

Member sinceJul 2026

Availability Details

Visa Status

Need Sponsorship

Relocation

Depends on Offer