Proficient in managing Security Operation Center with extensive experience in information security. Skilled in ArcSight SIEM, specializing in log management, use-case development, and custom parser creation. Expertise in Windows and Linux operating systems, network security strategies, and project management. Recognized for strong teamwork and effective problem-solving skills.
Overview
14
14
years of professional experience
1
1
Certification
Work history
Senior Engineer
Wipro Limited
Dubai, United Arab Emirates
07.2024 - Current
Maintained all SIEM components healthy and safe by taking appropriate action on time.
Developed custom parsers for unsupported log sources
Liaised with clients to gather specific project requirements.
Collaborated effectively with cross-functional teams, ensuring smooth project execution
Technical Specialist
Allianz Technology
Trivandrum, Kerala, India
08.2018 - 07.2024
Squad Lead for team of eight
Managed and maintained health of multiple SIEM components such as ESM, Logger, Smart Connectors, ArcMC, etc
Troubleshoot issues with SIEM components and get it resolved by contacting vendor if further support is required.
Kept all SIEM components and thereby organization safe by applying necessary patches for vulnerabilities on time.
Log source onboarding to SIEM for security monitoring and automatic incident generation as and when there are detections.
Developed custom parser for log sources those are not supported by ArcSight by default.
Developed new correlation rules and use cases for security monitoring
Provided technical insights, influencing product development strategies
Developed comprehensive documentation, improving knowledge sharing by 50%
Co-ordinate with Internal & External audit teams and provide required support.
Led cross-functional teams to deliver projects on time and under budget.
SIEM Consultant
Paladion Networks
India & Middle East
02.2012 - 07.2018
Squad Lead for team of six
Provided support to clients around globe with their SIEM related queries and concerns.
Administration and Health check of all SIEM (ArcSight) components
Expertise in implementation of multiple ArcSight components such as ESM, Logger, ArcMC, etc.
Co-ordinate with SMEs to perform log review and identify critical use cases with respect to risk factors, controls identified by Organization
Flex/Parser development to onboard log sources which are not directly supported by ArcSight
Maintain knowledge base articles which serve as reference for SIEM team members
Identify custom reporting requirements, translate it into SIEM technical specifications and implement it in SIEM
Prepare/review/comment on daily/weekly/monthly reports
Analyse and Investigate alerts, suspicious activities, traffic anomalies noticed in SOC monitoring tools and correlate as necessary with other sources or obtain feedback from respective SME
Education
Master of Computer Applications - Computer Applications