Back to Developers
Varun Thunagar

Varun Thunagar

SOC Analyst

Bangalore 4+ yrs exp 90 ยท Outstanding

About

To contribute as a SOC Analyst by applying hands-on experience in security monitoring, incident triage, threat analysis and incident response, while continuously strengthening the organisation's cyber security posture.

Skills & Expertise (29)

MITRE ATT&CK Advanced
8.5/10
4
Years Exp
Splunk Enterprise Security Advanced
8.0/10
4
Years Exp
Windows Advanced
8.0/10
4
Years Exp
SPL Advanced
8.0/10
4
Years Exp
KQL Advanced
8.0/10
4
Years Exp
LINUX Advanced
8.0/10
4
Years Exp
Microsoft Sentinel Advanced
8.0/10
4
Years Exp
CrowdStrike Falcon Advanced
8.0/10
4
Years Exp
Microsoft Defender for Endpoint Advanced
8.0/10
4
Years Exp
Microsoft Defender for Office 365 Advanced
7.5/10
4
Years Exp
PowerShell Advanced
7.5/10
4
Years Exp
IBM QRadar Advanced
7.5/10
4
Years Exp
VPN Advanced
7.0/10
4
Years Exp
SMTP Advanced
7.0/10
4
Years Exp
HTTPS Advanced
7.0/10
4
Years Exp
HTTP Advanced
7.0/10
4
Years Exp
DNS Advanced
7.0/10
4
Years Exp
IP Advanced
7.0/10
4
Years Exp
TCP Advanced
7.0/10
4
Years Exp
DHCP Advanced
7.0/10
4
Years Exp
ServiceNow Advanced
7.0/10
4
Years Exp
Tenable Nessus Advanced
7.0/10
4
Years Exp
Palo Alto Networks Advanced
7.0/10
4
Years Exp
Cisco Secure Firewall Advanced
7.0/10
4
Years Exp
WIRESHARK Advanced
7.0/10
4
Years Exp
ProofPoint Advanced
7.0/10
4
Years Exp
VirusTotal Advanced
6.5/10
4
Years Exp
MISP Advanced
6.0/10
4
Years Exp
AbuseIPDB Advanced
6.0/10
4
Years Exp

Work Experience

SOC Analyst

Luminare Technologies Limited

Dec 2021 - Present

Monitor and investigate security alerts in a 24x7 SOC environment from SIEM, EDR, firewalls, IDS/IPS, email security, proxy, VPN, Active Directory and cloud platforms. Perform Level 1 and Level 2 triage by validating alerts, collecting evidence, identifying affected assets and users, and determining incident scope, severity and business impact. Correlate logs across multiple sources and build clear incident timelines to understand attacker activity and support accurate decision-making. Investigate phishing and business-email-compromise alerts by analysing headers, sender infrastructure, URLs, domains, attachments and sandbox or reputation results. Analyse endpoint alerts involving malware, suspicious processes, persistence, credential access, lateral movement, unusual scripts and unauthorised software. Enrich indicators such as IP addresses, domains, URLs and file hashes using internal and external threat-intelligence sources. Map observed attacker techniques to the MITRE ATT&CK framework and document relevant tactics, techniques and indicators of compromise. Create, assign, update and track security incidents in ServiceNow and ensure response activities are completed within agreed service-level targets. Escalate confirmed or high-risk incidents to incident-response and engineering teams with investigation evidence, impact details and recommended containment actions. Support containment actions such as endpoint isolation, blocking malicious IPs, domains or hashes, disabling compromised accounts, resetting credentials and revoking active sessions. Review Windows Event Logs, Sysmon, Linux authentication logs, DNS, proxy, firewall, VPN, Microsoft 365 and cloud audit logs during investigations. Develop and refine KQL and SPL queries for alert validation, log correlation, threat hunting and detection-gap analysis. Conduct proactive threat-hunting activities for suspicious authentication patterns, unusual network connections, known indicators and abnormal user or endpoint behaviour. Recommend alert tuning, suppression and new detection use cases to reduce false positives while maintaining effective monitoring coverage. Monitor log-source availability and ingestion health, identify monitoring gaps and coordinate restoration with platform or infrastructure teams. Prepare shift handovers, incident summaries, operational dashboards and daily, weekly and monthly SOC reports for customers and internal stakeholders. Participate in incident calls, root-cause analysis and lessons-learned reviews, and maintain investigation evidence and audit-ready documentation. Create and update SOC playbooks, standard operating procedures and knowledge articles based on recurring incidents and newly identified threats. Track current security advisories, emerging threats and important vulnerabilities and coordinate appropriate validation or remediation activities.

Education

Bachelor of Science (B.Sc.) in Computers - Nova Academy of Rural Education and Research

- 2018 ยท Afghanistan

Certifications

No certifications added yet

Interested in this developer?

Profile Score Breakdown

๐Ÿ“ท Photo 10/10
๐Ÿ“„ Resume 10/10
๐Ÿ’ผ Job Title 10/10
โœ๏ธ Bio 10/10
๐Ÿ› ๏ธ Skills 20/20
๐ŸŽ“ Education 10/10
โฑ๏ธ Experience 15/15
๐Ÿ’ฐ Rate 0/5
๐Ÿ† Certs 0/5
โœ… Verified 5/5
Total Score 90/100

Profile Overview

Member sinceOct 2026