
Results-driven Cybersecurity professional with 10 + years of experience in Cyber Threat Hunting, Threat Intelligence, Malware Analysis, and Incident Response. Proven track record across global organizations including Big 4 consulting, managed security services, and enterprise environments. Adept at building proactive cyber Défense strategies, developing threat hunting libraries, and leading security operations in 24/7 environments.
April 2025 – Present
Diyar United Company (KOC)
Monitor security gaps 24/7 and identify potential compromises through log analysis across multiple security platforms.
Conduct end-to-end security event analysis by correlating alerts across Proofpoint, LogRhythm, and Extra Hop.
Identify root causes of security incidents and streamline threat detection and response workflows.
Leverage SIEM, NDR, and threat intelligence platforms to reduce false positives and improve incident response time.
Utilize sandboxing tools including Recorded Future to analyses and assess potential security threats.
Actively operate tools such as Anomali and Proofpoint to correlate security events effectively.
Feb 2023 – April 2025
Ernst & Young LLP
Led identification of successful and potential intrusions by analysing relevant security event data and distinguishing false positives from true threats.
Developed and maintained Threat Hunting Libraries based on the latest TTPs, IOCs, and IOAs aligned with MITRE ATT&CK.
Built actionable Threat Intelligence APIs integrated into Microsoft Sentinel SIEM for automated detection workflows.
Conducted deep research into APT groups, attribution analysis, and advanced TTPs to build 'indicators of behaviour' use cases.
Delivered proactive cyber Défense advisory to clients based on modern threat landscape analysis and OSINT.
Administered Symantec DLP and CrowdStrike EDR; handled multiple SIEM platforms at enterprise scale.
Performed advanced threat hunting: scenario-based, threat-intel-driven, and proactive methodologies.
June 2020 – Feb 2023
Mindtree Ltd
Analysed attacker’s behaviour using Windows Defender logs, applying Cyber Kill Chain, MITRE ATT&CK, and David Bianco's Pyramid of Pain frameworks.
Served as Shift Lead / SME, overseeing fellow researchers' work to ensure no True Positive cases were missed.
Investigated critical human adversary techniques: hands-on-keyboard activity, initial access, lateral movement, data exfiltration, and credential theft.
Delivered proactive (targeted) attack notifications to enrolled customers, warning of suspicious activity with detailed impact analysis.
Provided technical support and research on ransomware, advanced phishing campaigns, and APT engagements.
Raised product bugs and coordinated with customer teams regarding process updates and workflow improvements.
Mar 2019 – June 2020
Ernst & Young LLP
Worked on ArcSight, Qader, DNIF, and Splunk SIEM platforms in a 24x7 managed security environment.
Performed real-time monitoring, investigation, analysis, and reporting of security events from diverse sources.
Conducted threat hunting for client environments, delivering impact assessments and remediation recommendations.
Analysed potential threats against banking computing environments with focus on countermeasure TTPs.
Contributed to SIEM use case tuning and development to enhance detection capabilities.
July 2016 – Feb 2019
Paladion Networks
Worked on ArcSight SIEM for log monitoring, security information management, global threat monitoring, and anti-phishing.
Provided security intelligence reports including latest threats, advisories, news, and patch releases via dashboards.
Investigated events to identify false and true positives; managed incidents through to closure across cross-functional teams.
Handled policy violations, IPS, ASA, UTM, and Proxy alerts; fine-tuned ArcSight correlation rules to minimize false positives.
Provided anti-malware and defacement monitoring for client websites with detection and reporting workflows.
2011 – 2015
Dr. MGR Educational Research Institute, Chennai