About 6.2+ years of experience in Information Security with hands on experience on SIEM, Endpoint Security, Antivirus, Web Security Firewalls, Email Gateway Filters, IDS & IPS, DLP tools and Vulnerability assessment.
Operating Systems: Windows, Linux
SIEM: QRadar
Email gateway: Proofpoint, O365
Anti-Virus: Cylance
Web Gateway: Cisco Umbrella (Open DNS), Cisco Iron port
Endpoint/EDR: M365 Defender, Crowd Strike Falcon, Carbon black
Data loss prevention: Digital Guardian
IPS/IDS: Tipping point
Vulnerability Scanner : Nessus Security Center(Tenable)
Other tools: KE Studio, XSOAR, NetCraft
Ticketing Tool: ServiceNow, Jira
• Working as a Security Analyst in SOC operations for real-time monitoring, analyzing logs from various security/Industrial appliances
• Daily basis Health checkup of IBM QRadar like Auto Update(checks for any failed patch/update), Backup, Disk Memory Utilization and New Discovered Log sources.
• Generating the daily basis report of Generated Offenses and guiding the team members on investigation.
• On boarding of Linux, windows, Cisco Switches/Routers, Firewalls, Application Database(including MSSQL,MySQL, PostgreSQL etc) M365 defender, cloud fare and AWS.
• Creation of custom Application in Dsm editor.
• Creation of Custom Event properties and Mapping of event properties.
• Engagement in creation of CRE(Custom Rule Engine) Rule for generating the offense for any specific activity suggested by customer.
• Creation of custom Rule Email notification in Rules.
• Testing the CRE( Custom Rule Engine) Rule through Historical Run or Log run PL.
• Generation of Weekly and Monthly Reports for False positive offense and tuning the rules.
• Installing and upgrading the QRadar Application and Extension.
• Generating Report on Daily health checklist on QRadar.
• Developing the Use Cases Scenarios for offense creation and Testing.
• As a part of BFSI unit, involved in Real time Digital Risk protection using tool -Netcarft
• Hands on experience in investigating the Threats/IOC's
• Good experience in analyzing phishing\spam, forged mails along with performing header analysis of incoming emails and investigating them using Proofpoint and 0365.
• Checking and analyzing emails using Microsoft KE Studio.
• Providing E-mail security solutions through Proof Point and creating custom rules for the users and managing organizational Email list.
• Auditing and preventing any malicious events in the end point devices using Cylance.
• Creating Access Policies, URL whitelisting\Blacklisting, URL Bypassing and Reporting using Cisco WSA proxy (Iron port).
• Capable of whitelisting and blacklisting domains to ensure network safety and analyzing
domain logs to detect and respond to security threats, ensuring network integrity using Zscaler.
• Checking the domains logs and whitelisting\blacklisting the domains using CISCO Umbrella.
• Analyzing the network intrusions with deep discovery inspector Tipping point and updating rules and signatures.
• Analyzing Malware events triggered in Trend Micro Tipping Point, Identifying Effected Systems & Reporting and generating detail Report on Malware Events.
• Performing threat analysis and mitigating or classifying it as benign.
Analyzing the mail data flow from internal network to outside organizational network using Digital Guardian DLP.
• Conducting vulnerability assessments and keeping a check on vulnerabilities on a regular basis using Nessus.
• Proficient in handling diverse security alerts, including unfamiliar sign-in properties, logins from anonymous IPs, detection of malicious URL clicks, and mitigating password spray attacks, ensuring robust protection of digital assets and user privacy.
• Good knowledge on Incidents involving threats like Ransomware, Malware Uncleaned Machines, Bot C & C activity, Data Outbound transfers, Excessive firewall deny events etc.
• Creating Use Cases and playbooks in GitHub based on requirements.
• Coordinating with vendors for operational issues.
• Documenting the procedure/technologies and actively participating in knowledge transfers and contributing to adhere to SOP's.
• Managing user requests, Shift Handovers, striving for customer satisfaction.
• Generating Iron Port, RSA DLP Reports weekly and monthly.
• Good communication and presentation skills.
Date of Birth: 27-04-1995
Languages Known: English, Telugu, and Hindi.
Permanent Address: 25-5-174/3, Kazipet, Hanamkonda, Warangal, Telangana, 506003.
I hereby solemnly affirm that all the information furnished by me is true to the best of my knowledge.
SIGNATURE : Nagaraj Alpula
DATE