Rohith جودافالي, Threat analyst

Rohith جودافالي

Threat analyst

Hcl Technologies

البلد
الهند - حيدر اباد
التعليم
ماجستير, Computer Sciences and Electronics streaming
الخبرات
6 years, 1 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :6 years, 1 أشهر

Threat analyst في Hcl Technologies
  • الهند - حيدر اباد
  • نوفمبر 2019 إلى مايو 2022

Monitoring, Analysing and managing the real time events
for the security devices using SIEM tool.
• Perform detailed analysis of Phishing mails and submit the
analysis to Cyber Defense Team for further action.
• Validating the phishing mail by examining the mail headers,
URL, IP reputations, attachments and identifying impact of
them.
• Analysing the attachment and URL's by dynamic method using
Cisco threat grid.
• Monitoring, troubleshooting, and triaging of incidents related
to attacks like DDOS, Ransomware, and Credential validation
attack & Mitre Attack
• Analyze the application that triggered Symantec, MDATP and
CS endpoint protection alert using the application information,
its hash and logs to white list the application from the firm.
• Experience in Incident Response management with Red team.
• Responsible for proactive threat analysis and activities across
the network leveraging intelligence from multiple internal and
external sources
• Conduct threat hunt operations using known adversary as well
as Indicators of Attack (IOA) in order to detect adversaries with
persistent access to the enterprise
• Actively check for Industry and Region-specific IOCs and Threat
actors.
• Conducts technical analysis on impacted systems to determine
impact, scope, and recovery from active and potential cyber
incidents
• Good Exposure in Incident Management and Project
Management
• Practical Insights to creation of Rules, Dashboards, Reports & Custom
Properties.
• Involved with customer on weekly calls to understand their
requirements and act accordingly to provide them better service

IT Security Analyst في Optum Global Solutions
  • الهند
  • مايو 2018 إلى أغسطس 2019

Working in a SOC (Security Operation centre) with multiple clients on Real Time Threat Management using SIEM
• Involved in 24*7 security event monitoring analysis, triage incident alerting and reporting for multiple clients
using SIEM.
• Identification, investigation and escalation of security threats to client-side security team.
• Performs Real time log monitoring, Security incident handling, investigation, escalation of security incidents with
recommendations to mitigate the threat.
• Practical Insights to creation of Rules, Dashboards, Reports & Custom Properties
• Introduced Shift Handover report for better communication between each shift.
Associate Analyst,

Associate Security Analyst في Tech Mahindra
  • الهند - حيدر اباد
  • فبراير 2016 إلى مارس 2018

Conduct threat hunt operations using known adversary as well as Indicators of Attack (IOA) in order to detect adversaries with persistent access to the enterprise.
Actively check for Industry and Region-specific IOCs and Threat actors.
Conducts technical analysis on impacted systems to determine impact, scope, and recovery from active and potential cyber incidents
Good Exposure in Incident Management
Practical Insights to creation of Rules, Dashboards, Reports & Custom Properties.
Involved with customer on weekly calls to understand their requirements and act accordingly to provide them better service.

الخلفية التعليمية

ماجستير, Computer Sciences and Electronics streaming
  • في XIBM
  • مارس 2018

Network Systems

ماجستير, Network Systems
  • في XIBM
  • يناير 2018

(

Specialties & Skills

Microsoft CRM
SIEM Qradar
Cyber Security
EDR Tools
Log Analytics
ANALYSIS
MICROSOFT ACCESS
NETSCAPE ENTERPRISE SERVER
NETWORKING
Microsoft Defender for Cloud
Azure Sentinel

اللغات

الانجليزية
متمرّس
الهندية
متمرّس

التدريب و الشهادات

SPLUNK (الشهادة)
تاريخ الدورة:
August 2020

الهوايات

  • Cloud Security, SIEM , Azure Security