Varun Thunagar
SOC Analyst
About
To contribute as a SOC Analyst by applying hands-on experience in security monitoring, incident triage, threat analysis and incident response, while continuously strengthening the organisation's cyber security posture.
Skills & Expertise (29)
Work Experience
SOC Analyst
Luminare Technologies Limited
Dec 2021 - Present
Monitor and investigate security alerts in a 24x7 SOC environment from SIEM, EDR, firewalls, IDS/IPS, email security, proxy, VPN, Active Directory and cloud platforms. Perform Level 1 and Level 2 triage by validating alerts, collecting evidence, identifying affected assets and users, and determining incident scope, severity and business impact. Correlate logs across multiple sources and build clear incident timelines to understand attacker activity and support accurate decision-making. Investigate phishing and business-email-compromise alerts by analysing headers, sender infrastructure, URLs, domains, attachments and sandbox or reputation results. Analyse endpoint alerts involving malware, suspicious processes, persistence, credential access, lateral movement, unusual scripts and unauthorised software. Enrich indicators such as IP addresses, domains, URLs and file hashes using internal and external threat-intelligence sources. Map observed attacker techniques to the MITRE ATT&CK framework and document relevant tactics, techniques and indicators of compromise. Create, assign, update and track security incidents in ServiceNow and ensure response activities are completed within agreed service-level targets. Escalate confirmed or high-risk incidents to incident-response and engineering teams with investigation evidence, impact details and recommended containment actions. Support containment actions such as endpoint isolation, blocking malicious IPs, domains or hashes, disabling compromised accounts, resetting credentials and revoking active sessions. Review Windows Event Logs, Sysmon, Linux authentication logs, DNS, proxy, firewall, VPN, Microsoft 365 and cloud audit logs during investigations. Develop and refine KQL and SPL queries for alert validation, log correlation, threat hunting and detection-gap analysis. Conduct proactive threat-hunting activities for suspicious authentication patterns, unusual network connections, known indicators and abnormal user or endpoint behaviour. Recommend alert tuning, suppression and new detection use cases to reduce false positives while maintaining effective monitoring coverage. Monitor log-source availability and ingestion health, identify monitoring gaps and coordinate restoration with platform or infrastructure teams. Prepare shift handovers, incident summaries, operational dashboards and daily, weekly and monthly SOC reports for customers and internal stakeholders. Participate in incident calls, root-cause analysis and lessons-learned reviews, and maintain investigation evidence and audit-ready documentation. Create and update SOC playbooks, standard operating procedures and knowledge articles based on recurring incidents and newly identified threats. Track current security advisories, emerging threats and important vulnerabilities and coordinate appropriate validation or remediation activities.
Education
Bachelor of Science (B.Sc.) in Computers - Nova Academy of Rural Education and Research
- 2018 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (29)
Click a skill to find developers with the same skill