Senior SOC Analyst with 5+ years of experience in enterprise and MSSP environments, specialising in high-severity incident response, threat hunting, and XDR-driven investigations.
Trusted escalation point for critical security incidents, making real-time containment decisions based on business impact and risk.
- End-to-end incident handling (Detection → Investigation → Containment → Recovery → RCA)
- High-severity alert triage and escalation (L2/L3)
- Business-impact-driven decision making
- Stakeholder communication (technical & executive level)
- Hypothesis-driven threat hunting
- Detection engineering and alert tuning
- False positive reduction and signal optimisation
- Splunk (Search, correlation rules, dashboards)
- IBM QRadar
- CrowdStrike Falcon (EDR/XDR)
- Microsoft Defender & Sentinel
- Multi-telemetry correlation (endpoint, identity, network, email)
- Malware analysis (Any.Run, VirusTotal)
- Log analysis (Windows Events, Sysmon, network logs)
- Simulated and investigated brute-force attack scenario
- Correlated logs across network and endpoint telemetry
- Identified attacker behaviour and attack patterns
- Mapped activity to MITRE ATT&CK (T1110)
- Performed containment strategy and remediation planning
- Developed detection use cases in Splunk
- Built dashboards for security monitoring
- Tuned alerts to reduce false positives
- Created detection rules aligned to attacker techniques
- Simulated adversary behaviour
- Improved detection coverage
- Evaluate alerts based on risk, context, and business impact
- Decide between containment vs monitoring strategies
- Lead investigations without dependency
- Translate technical findings into actionable business insights
- Advanced Detection Engineering
- XDR-based Threat Hunting
- SOC Automation (AI + Security)
- Cloud Security Monitoring
- CISM
- CompTIA Security+
- ISC2 Certified in Cybersecurity
- Cybersecurity SOC Analyst & Professional
- Cybersecurity Ethical Hacking Professional
- CompTIA Network+ | CompTIA A+
- ITIL 4 Foundation
- Website: https://cybertechnology.in
- LinkedIn: https://www.linkedin.com/in/sandeepmothukuris
- Email: sandeep.mothukuris@gmail.com
Delivering high-confidence detections, minimizing false positives, and enabling rapid response to critical threats in enterprise SOC environments.