Vidya T
Threat Hunter | SOC Analyst L2
About
Threat Hunter and SOC Analyst (L2) with 5+ years of experience proactively identifying, investigating, and mitigating advanced threats across enterprise, cloud, and hybrid environments. Skilled in hypothesis-driven threat hunting mapped to the MITRE ATT&CK framework, using Microsoft Sentinel, Hunters SIEM, Splunk, Defender XDR, and CrowdStrike Falcon to uncover IOCs, IOAs, and hidden attacker behavior. Experienced investigating APTs, ransomware, insider threats, and phishing/BEC campaigns, performing malware analysis, root cause analysis, and cross-team incident response. Skilled in vulnerability management and patch management, including scanning, risk-based prioritization, and remediation tracking to reduce enterprise attack surface. Proven track record reducing false positives, improving detection fidelity, and mentoring L1 analysts in fast-paced SOC operations.
Skills & Expertise (62)
Work Experience
SOC Analyst – Level 2
Coforge
Dec 2023 - Present
Led proactive, hypothesis-driven threat hunting operations using behavioral analytics, IOC matching, UEBA, and anomaly detection; identified 10+ advanced persistent threats before escalation. Investigated advanced persistent threats, ransomware, phishing, business email compromise (BEC), malware infections, and insider threat incidents; coordinated containment and eradication with IT and IR teams. Analyzed multi-source security telemetry in Hunters SIEM, correlating logs across endpoint, identity, and cloud to surface suspicious behaviors, lateral movement, and attack patterns. Monitored and triaged security alerts using Microsoft Sentinel and Defender XDR across endpoints, Azure workloads, identity, and SaaS applications; maintained 98%+ SLA adherence. Conducted endpoint investigations and malware analysis using CrowdStrike Falcon EDR, including process tree review and containment of compromised hosts. Performed root cause analysis (RCA) and post-incident reviews for confirmed security events, documenting findings and remediation recommendations. Enriched alerts with IOC reputation, threat actor TTPs, and emerging attack trends using Cyble Threat Intelligence, improving alert fidelity and response speed. Correlated SIEM, EDR, vulnerability, and threat intelligence data to reduce false positives by 30%, sharpening focus on high-priority incidents. Managed vulnerability management and patching lifecycle using Orca Security, running scans, assessing exploitability and business impact, and coordinating remediation and patch deployment with IT teams; reduced open critical findings by 35%. Performed SIEM log correlation between Sentinel, Entra ID, and Defender to identify unauthorized logins, privilege escalation, and lateral movement paths. Worked with Intune policies to verify endpoint compliance, enforce patch deployment, and isolate high-risk devices during active incidents, significantly reducing dwell time. Conducted periodic security audits aligned with ISO 27001 and SOC 2 frameworks in collaboration with IT and compliance teams. Mentored L1 analysts on alert prioritization, escalation procedures, SOAR playbooks, and IOC triage methodologies. Authored and maintained incident response playbooks, SOPs, and knowledge base articles for recurring event patterns. Designed and operationalized custom threat hunting queries (KQL, SPL) in Sentinel and Splunk to surface living-off-the-land binaries, fileless malware, and C2 beaconing patterns undetected by existing correlation rules, expanding detection coverage across the MITRE ATT&CK matrix. Built a structured, intelligence-led threat hunting cadence — combining hypothesis generation, adversary emulation, and ATT&CK-based gap analysis — to proactively uncover stealthy persistence and privilege escalation techniques ahead of automated detection. Owned end-to-end patch management governance for critical and zero-day vulnerabilities, driving emergency patch cycles across 1,000+ endpoints via Orca Security and Intune and reporting SLA compliance metrics to leadership. Partnered with IT infrastructure teams to design a risk-based patch prioritization framework (CVSS score, exploit availability, asset criticality), cutting mean-time-to-patch for critical CVEs and reducing recurring audit findings.
SOC Analyst – Level 1
Coforge
Aug 2021 - Nov 2023
Conducted threat hunting to detect credential misuse, privilege escalation, and persistence techniques mapped to MITRE ATT&CK tactics and techniques. Assisted senior analysts in building baseline behavioral profiles for critical assets, enabling faster identification of anomalous activity during proactive threat hunts. Performed 24x7 real-time monitoring and triage of security alerts and logs using Splunk and Splunk Phantom SOAR across a multi-client environment. Investigated phishing emails, user lockouts, endpoint detections, and suspicious network activity using Microsoft Defender for Endpoint and CrowdStrike Falcon. Verified alert legitimacy through multi-source reputation checks using VirusTotal, AbuseIPDB, and AlienVault OTX before escalating confirmed incidents. Validated and tuned SIEM detection rules and correlation searches to reduce false positives and improve detection efficiency. Supported vulnerability scanning and patch compliance checks, flagging unpatched and missing critical updates on endpoints for remediation. Tracked patch deployment SLAs across Windows and third-party applications, coordinating with IT teams to close out overdue critical and high-severity patches. Escalated validated security incidents to L2/L3 teams following established SOPs and incident classification guidelines. Documented security incidents, investigation timelines, and IOCs; maintained knowledge base of recurring event patterns. Supported threat intelligence correlation, IOC enrichment, and weekly threat landscape reporting for security leadership. Executed and managed phishing simulation campaigns via KnowBe4; delivered security awareness metrics and training effectiveness reports. Monitored SIEM dashboards and generated daily/weekly security operations reports highlighting trends and open incidents.
Education
MBA - PSCMR College of Engineering
- 2019 · Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Need Sponsorship
Relocation
Depends on Offer
Skills (62)
Click a skill to find developers with the same skill
Similar Profiles
shivakumar p
SOC Analyst | 2+ Yrs SOC | 5 Yrs Network Security | 7+ Yrs IT | IBM QRadar | Threat Detection & Incident Response
Rahul K
Security Monitoring and Threat Detection Analyst
Indrajeet Deshmukh
SOC Analyst | Threat Detection | SIEM Tools Expertise
Chinmay Mendse
SOC Analyst | TryHackMe SAL-1 Certified | Blue Team | SIEM • Threat Detection • Incident Response | Ex-Software Developer