Lead Senior Security Analyst at Cogeco Connexion (2023-07 – Present)
Security Operations Centre, Detection and Incident Response
- Handle the daily monitoring and triage of security alerts in Splunk and Microsoft Sentinel, and take the escalations that the junior analysts are not able to close on their own.
- Investigate phishing, malware and suspicious login cases from start to finish, using EDR telemetry from CrowdStrike and Defender along with log analysis to work out what actually happened.
- Carry out containment when an incident is confirmed, such as isolating the affected host or disabling the compromised account, and then prepare a clear root cause report for the stakeholders.
- Tune detection use cases and reduce false positives based on what we keep seeing in the queue, which has helped the team trust the alerts a lot more.
- Run threat hunts now and then based on fresh threat intelligence, and map the findings to MITRE ATT&CK so that the gaps turn into new detections.
- Led a SIEM migration where a set of detection use cases were moved from a legacy SIEM into Microsoft Sentinel. Rebuilt the analytics rules in KQL, validated them against sample data and documented each one with its data source and ATT&CK mapping, so that the migration went live without losing detection coverage.
- Brought down the false positive rate on the high volume alerts by close to 30 percent through better tuning and allow listing, which saved the team a fair amount of effort every shift.
- Helped reduce the response time on priority incidents by setting up a few SOAR playbooks for common cases like phishing and known bad file hashes.
- Mentored two junior analysts and prepared investigation runbooks that the team still uses for the routine alert types.
- Received a Spot Award from the delivery head for handling a major phishing incident over a weekend and keeping the client updated throughout. Also got a Star Performer mention in the quarterly review for the detection tuning work.
Security Analyst at Mindtree (2018-07 – 2022-12)
24x7 Managed SOC, Banking and Retail Clients, Tier 2
- Worked as a Tier 2 analyst in a round the clock SOC supporting banking and retail clients, taking escalations from Tier 1 and running them down using Splunk.
- Investigated phishing and malware alerts, did email header and attachment analysis, and removed malicious mails from user mailboxes through Defender for Office 365.
- Performed first level containment such as host isolation and account disablement, and escalated to the incident response team when a case went beyond the normal runbook.
- Used MITRE ATT&CK to frame investigations and started doing basic threat hunting on the side, which surfaced activity that the standard alerts were missing.
- Built a set of correlation rules in to detect brute force and impossible travel scenarios for one of the banking clients. Worked closely with the client team to fine tune the thresholds so that the rules stayed useful without flooding the analysts with noise.
- Was part of the team that improved the SOC alert closure time, and kept one of the best closure rates in the shift over several months.
- Created phishing response runbooks that became the standard for the Tier 1 analysts, which made the handoffs much smoother.
- Received an On the Spot award for quick handling of a ransomware alert for a retail client, where early isolation stopped it from spreading further. The client point of contact also appreciated the consistent quality of the investigation notes in writing.
Associate Security Analyst at Sify Technologies (2017-06 – 2018-07)
Security Operations Centre, Tier 1
- Started as a Tier 1 analyst monitoring the SIEM and EDR queues on rotating shifts, doing first level triage against the runbooks and escalating real incidents with the context already collected.
- Worked on phishing and commodity malware alerts as the first responder, and did basic enrichment using VirusTotal and AbuseIPDB before escalating.
- Logged and tracked cases in ServiceNow, made sure the SLA timers were respected, and handled clean shift handovers so that nothing was dropped between shifts.
- Helped onboard log sources for a new client into the SIEM, including Windows event logs and firewall logs, and verified that the parsing and field mapping were correct so that the data was actually usable for detection.
- Picked up the investigation basics quickly and was moved to handle slightly higher priority alerts ahead of the usual timeline.
- Maintained good accuracy on alert classification, which reduced the rework for the senior analysts.
- Received a Rising Star award in the first year for fast learning and for being reliable on the night shift.