About
Cyber Security Analyst with 2+ years of hands-on experience using SIEM tools including Splunk and Microsoft Sentinel within a 24x7 security operations environment. Strong practical understanding of TCP/IP, DNS, HTTP/HTTPS, VPNs, and network security gained through daily log correlation across firewalls, IDS/IPS, and EDR platforms (CrowdStrike Falcon, Microsoft Defender for Endpoint). Skilled in incident response, threat detection, and log analysis, with hands-on investigation experience across common cyber threats including malware, phishing, and insider/unauthorized-access activity. Familiar with Windows and Linux security event and authentication log review, and experienced applying the MITRE ATT&CK framework to strengthen investigation context. Strong analytical, troubleshooting, and documentation skills, with a collaborative approach to incident resolution.
Skills & Expertise (38)
Work Experience
Cyber Security Analyst
Cipla Limited
Jul 2024 - Present
Use Splunk and Microsoft Sentinel daily to triage ~40–50 priority-based alerts per shift, applying strong practical knowledge of TCP/IP, DNS, HTTP/HTTPS, and VPN traffic to identify network-level threats within a 24x7 SOC. Analyze firewall, IDS/IPS, VPN, and proxy logs alongside EDR telemetry (CrowdStrike Falcon, Microsoft Defender for Endpoint) to correlate suspicious activity across source/destination IPs and affected hosts. Perform incident response and threat detection by conducting severity classification, evidence capture, and containment recommendations — host isolation, password resets, firewall rule changes — for confirmed threats. Investigate common cyber threats including phishing (15–20 weekly) and malware/endpoint alerts, analyzing headers, URLs, attachments, file paths, command lines, and process trees to determine true/false positives. Detect insider-threat and unauthorized-access indicators by analyzing authentication activity — brute-force attempts, failed logins, account lockouts, VPN anomalies, and impossible-travel patterns. Perform log analysis across Windows Security Events and Linux authentication logs to identify anomalous activity and support security administration awareness across both operating systems. Conduct IOC-based analysis on IPs, domains, URLs, and file hashes using VirusTotal, AbuseIPDB, and URLScan, and map findings to MITRE ATT&CK techniques to strengthen investigation context. Document 10+ incident tickets weekly in ServiceNow/Jira with investigation summary, evidence, impact analysis, and closure comments, maintaining strong analytical and documentation standards. Collaborate with Network, Wintel, Linux, Cloud, and Security Engineering teams on alert validation, containment, and remediation follow-up, applying troubleshooting and problem-solving skills across cross-team investigations. Participate in shift handovers, daily alert reviews, and SLA tracking, contributing to consistent SOC operational reporting.
Education
Bachelor of Computer Application (BCA) - Savitribai Phule Pune University
2023 - 2026 · India
Certifications
Executive Vulnerability Management Training
Cybrary · 2026
Incident Response Lifecycle Training
Cybrary · 2024
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Need Sponsorship
Relocation
Open to Relocation
Skills (38)
Click a skill to find developers with the same skill