Sr SIEM/Cybersecurity and SOCEngineer
Roshan Chowdary Kodali
Phone#:940-***-****
**********@*****.***
sProfessional Summary:
Senior SIEM/ Threat Detection and SOC Engineer with 6+ years of experience in administration, development, and securityoperations. Proven expertise in threat detection, SIEM, SOAR, EDR, and log management in both on-
prem and cloud environments (AWS, Azure). Adept in Splunk ES, ITSI, and integrating enterprisesecurity tools like App Dynamics, Dynatrace, ELK, Kibana, Grafana, New Relic, CrowdStrike,Symantec DLP and Firewalls, Web Application Scanner, Vulnerability Scanners, Malware Research Tools or Forensics Tools. Proficient in scripting,automation (Ansible, Bash, Shell, Python), and implementingDevops tools like GitHub Actions, Jenkins, CodePipeline, etc
Technical Skills:
Operating Systems: Red Hat Linux (RHEL) (4.x, 5.x, 6.x) Unix, Linux Ubuntu, Windows 2012R2/2016.
Tools used: Splunk 5x/6x/7x/8x Oracle 11g/10g/9i/8i/7.3, Data dog, App Dynamics, Dynatrace, chef, puppet, Jmeter, Service now, Git, JIIRA, Tomcat, IBM Q Radar, New relic, Data Analyst, ELK, Bigpanda
Databases and Clouds: Oracle, MYSQL SERVER, GCP, AWS and Azure
Version Control System: Git, Git hub, Git Lab, Bit Bucket,
Scripting Languages: Shell, Bash, shell scripts, Ansible, Python.
Networking and Protocols: FireEye, TCP/IP, HTTP, UX, SIP, IOS, 5G, HTTPS, SSH, SCP, SFTP, SME, DHCP, Docker, ELK, Kibana, Datadog, Crowdstrike, Networks, Switches, SCCM, Routers, DNS, ZFS, LDAP, HEC, CMMC, NIST 180, CSF, ISO 27001, Kubernetes, SignalFX, SOAR, Pager Duty, EDR, Netcool, Firewall, SNMP, ArcSight, ITSM, MLTK, PCI, APM, LDAP, SDLC, SOC, IaaS, SIEM, ITSI, rsyslog, syslog-ng.
Splunk Modules: Splunk Enterprise,Splunk Cloud, Splunk ES, Cribl, SOAR, Splunk ITSI
Certifications:
Splunk- User, power User, Splunk Admin, Developer and Splunk ES Admin Certified, certification of Deloitte Splunk>Partner Associate Managed Service Provider
Completed AWS Essential Training Certified Completed Azure Fundamentals Training Certified
eBay October 2025 - Present
Sr SOC/ Splunk Architect/ Administrator
Responsibilities:
Administered and supported enterprise-level Splunk environments with high data ingestion volumes.
Designed, implemented, and maintained distributed Splunk architectures including Indexer Clusters, Search Head Clusters, Heavy Forwarders, and Deployment Servers.
Performed capacity planning and license management, forecasting data growth and optimizing storage to prevent performance degradation and license violations.
Executed Splunk upgrades and migrations (minor and major versions) using rolling upgrade strategies with minimal downtime.
Onboarded and normalized log data from Linux, Windows, cloud platforms, applications, databases, and security tools.
Developed and maintained inputs.conf, props.conf, and transforms.conf for accurate parsing, field extraction, timestamp handling, and CIM compliance. Monitored Splunk health using internal logs and monitoring dashboards, proactively resolving issues related to indexing latency, search performance, and system resources.
Troubleshot and optimized slow searches and dashboards by improving SPL queries, leveraging summary indexing, and accelerating data models.
Implemented role-based access control (RBAC) to enforce secure and compliant access to indexes, dashboards, and knowledge objects.
Integrated Splunk with LDAP/SAML authentication, ensuring centralized identity management and security compliance.
Supported SOC and incident response teams by maintaining log availability, retention policies, and fast search performance during investigations.
Automated routine administrative and monitoring tasks using Python and shell scripting, improving operational efficiency.
Worked closely with infrastructure, application, and security teams to onboard new use cases and align Splunk solutions with business needs.
Ensured compliance with logging, retention, and audit requirements across regulated environments. Served as a Splunk Subject Matter Expert (SME)
Open AI June 2023 – September 2025
Sr Splunk/Threat Detection and SOC OperationsEngineer
Responsibilities:
Built and maintained Splunk components by planning the platform growth and support Splunk on UNIX, Linux and Windows-based platforms, Assist with automation of processes and procedures.
Served as on-call lead for monitoring infrastructure (Splunk, EDR, SOAR), coordinating resolution across a cross-functional team of 4+ engineers.
Designed and implemented observability pipelines using Cribl Stream to process logs, metrics, and traces from multiple sources (AWS CloudWatch, Syslog, Kubernetes, and API endpoints) into destinations like Splunk, S3, and Datadog.
Operated and hardened a multi-site Splunk Enterprise environment (indexer clustering, SHC, deployer, DS) with RF/SF validation, bucket health checks, and NFS tuning; executed upgrades, patching, license management, and DR failover drills.
Monitored and tuned ingestion/search/storage pipelines (queue depths, scheduler load, bucket replication) reducing P95 search latency by 28% and cutting skipped searches by 32%. Designed and enforced props.
conf/transforms.conf standards for timestamping, line-breaking, field extractions, and value normalization; improved parsing accuracy by 40%.
Led data onboarding projects across on-prem, AWS, Azure, Kubernetes using forwarders, syslog, HEC; ensured retention planning, audit readiness, and compliance with PCI/NIST standards.
Developed data routing rules to send critical logs to Splunk for real-time monitoring while archiving full-fidelity raw data to Amazon S3 for compliance and cost optimization.
Created data transformation pipelines in Cribl to normalize log formats, enrich events with metadata (host details, region, app ID), and mask sensitive fields such as PII and authentication tokens.
Mentored junior engineers and conducted pair programming sessions to review correlation rule logic and infrastructure configurations.
Integrated Cisco ASA, Firepower, Umbrella, and AMP with Splunk and SOAR to enhance threat visibility, automate response, and reduce false positives by 30%.
Built and fine-tuned Forcepoint DLP and CASB policies to prevent sensitive data exfiltration across email, web, and cloud platforms.
Designed and developed high-performance backend APIs using FastAPI and Python to integrate ZK proof workflows into internal SOC automation tools.
Built and deployed concurrent Rust-based microservices to handle Solana smart contract interactions and proof submissions across dev/test networks.
Implemented and tested zk-SNARK circuits using Circom and snarkjs for data privacy use cases, integrating with Python backend via WebAssembly (WASM).
Integrated distributed prover infrastructure with Kubernetes and Docker, enabling parallel proof generation, horizontal scaling, and performance monitoring with Grafana.
Experimented with cryptographic primitives including Halo2 and Poseidon hash functions, contributing to secure and efficient ZK workflows.
Developed and automated incident response playbooks for Forcepoint and Cisco alerts, aligned with MITRE ATT&CK and NIST standards.
Implemented regex-based field extraction and custom JavaScript functions in Cribl for advanced parsing and enrichment.
Partnered with security teams to route security logs simultaneously to SIEM (Splunk/QRadar) and cloud analytics platforms (Datadog/Elastic) to support threat detection and incident response.
Leveraged Cribl Search for federated queries across S3 buckets and Splunk indexes without moving the data, reducing operational overhead. Automated deployment of Cribl pipelines using CI/CD with GitHub Actions and Terraform, ensuring version-controlled configurations and consistent environments.
Implemented Microsoft Sentinel for real-time monitoring, log ingestion, and correlation across hybrid workloads (Azure, O365, endpoints).
Created detection rules, custom workbooks, and threat analytics in Sentinel, integrating with ServiceNow and Power BI for reporting.
Installed, Integrated and Maintained many security applications like CSPM and identifying the threat detection false positives and creating runbooks.
Designed and maintained Python-based data ingestion pipelines for structured log processing and enrichment, aligned with scalable ETL architecture.
Integrated and automated detection rules and runbooks using Python scripts and API calls, improving threat response automation efficiency.
Led zero-to-one development of internal RAG (Retrieval-Augmented Generation) proof-of-concept leveraging OpenAI APIs and internal vector search mechanisms (FAISS), contributing to early-stage LLM application in SOC.
Implemented API endpoints using FastAPI for internal dashboards and tool integration to streamline threat hunting operations and SOC playbook access.
Experimented with LLM prompt tuning and audit tracking to explore explainability and reduce hallucinations in SOC alert summaries.
Collaborated with DevOps team to productionize infrastructure using Terraform and GitHub Actions, ensuring CI/CD pipeline support for Splunk and LLM microservices.
Integrated observability platforms like Datadog, Dynatrace, New Relic, and Grafana for performance tracking, uptime monitoring (99.9%), and scalable alert systems.
Responsible for every Splunk Enterprise, Cloud and ES Administration and Development tasks like onboarding data from sources, developing advanced dashboarding, Alerts, Correlations, and reporting.
Responsible in SOC, Incident response, EDR, Detection engineering, runbooks and advanced playbooks creation threat analysis and event management practices. Also, tuning out false positives and automating playbooks.
As a Responsible and on call team lead for Splunk, New Relic, Data dog, Crowdstrike and other monitoring tools
Combine CrowdStrike EDR data with other logs to perform root cause analysis and Analyze CrowdStrike detection alerts within Splunk to identify malicious activity and Creating Detection Rules
Integrated with AWS with Security lake, CSPM, ASM, Created Detection rules in Splunk ES with added multiple Actions like notables, playbooks etc. Also, created runbooks as well.
Involved on SOAR Automation and Deployments Integrated SOAR with a wide range of security tools (SIEM, EDR, DFIR, threat intel feeds, ticketing systems, and firewalls) to enable automated, end-to-end response workflows.
Monitored and Mitigated the the DDOS and DOS attacks and resolved them, created runbooks
Monitor and Modify the New relic synthetic scripts and adding and removing new or not active user accesses
Created Splunk Dashboards to highlight key business metrics such as transaction volume and average processing time, as well as to measure the performance of other third-party systems.
Collaboratively worked with the cloud team to add the Splunk forwarder image on United Airlines AMI (amazon machine image) which includes inputs and outputs apps that are connected to Splunk Cloud.
Fixed the issues like improper parsing, line breaking and time stamping. Configured LDAP on all Splunk servers.
Installed and Configured Dynatrace app and add-on and Ingested the Metrics, logs. Created comprehensive dashboards, alerts
Integrated with CyberArk, Dynatrace, Crowdstrike, Zscaler, IBM Guardiun and Other Applications with Splunk
Deployed the Symantec logs and kafka into our Splunk. Integrated and Responsible for every ServiceNow Tickets and Provided on call support as well.
Integrated with Cortex XSOAR for network devices and cloud platforms and other tools, Created, Incident response workflows using Notable events and Automated with SOAR playbooks, MITRE and ATT&CK and Risk analysis for monitoring.
Collaborate with various project team members and external personnel to monitor, manage, resolve incident, problem tickets, and adjust as needed.
Deployed/configured Splunk on various platforms with cross search functionality (On-prem and AWS). Validating. The HEC tokens with using Postman. Performed Search time field extractions with regex and created many regex queries.
Experienced on Splunk SOAR and Monitored all Splunk MITRE and ATT & CK framework data events, working
Ingesting Symantec Data Loss Prevention (DLP) logs into Splunk can help organizations monitor and analyze data security events to prevent data breaches and ensure compliance
Created Dashboards, Alerts and mapped into MITRE framework to monitor security and threat events identified.
As ES admin worked on Incident responses, Security Operations and Threat Analysis. Normalizing Splunk data ensure all fields are mapping with CIM and bringing data to Splunk ES.
Implementing CI/CD for Splunk with Deployment Apps folder from Deployment Server into GitHub by using branches and pull requests to make changes and kicking the Jenkins pipeline to Clone the git repository followed by SSH into the DS and copying the files to Deployment Server and restarting the Splunk.
Implemented Cribl Stream pipelines to optimize observability data flow across cloud and on-prem environments, reducing Splunk ingestion costs by 30%.
Built data transformation and enrichment rules to normalize log formats, mask PII, and append contextual metadata for improved analytics.
Designed multi-destination routing strategies, sending high-value logs to Splunk while archiving raw data in S3 for compliance and long-term retention.
Configured Cribl Edge agents for distributed data collection across Kubernetes and Linux hosts, ensuring secure and scalable telemetry ingestion.
University of North Texas Feb 2022 – May 2023
Sr Splunk/SIEM/SOCEngineer
Responsibilities:
Developed Splunk Dashboards, searches and reporting to support various internal clients in Security, IT Operations and Application Development.
Migrated large-scale log pipelines (from ELK to Splunk Cloud), optimizing data normalization and structured threat intelligence workflows.
Developed proof-of-concept smart contracts on Solana using Rust and Anchor, enabling token-gated access and log validation workflows.
Conducted hands-on testing of ZK circuits using Circom and incorporated them into Python-based alert correlation engines for security automation.
Built RESTful microservices to simulate ZK proof generation pipelines and integrated monitoring via Splunk and Datadog.
Participated in research-driven implementation of zkVMs to analyze cryptographic audit trails in SOC data.
Contributed to backend performance optimization of proof and alert systems deployed on AWS and GCP cloud infrastructure using Docker containers.
Implemented Python scripts and HEC pipelines for batch processing and log onboarding — restructured for modular ingestion with schema validation.
Built custom dashboards and reporting tools for security event correlation — mapped to frameworks like MITRE ATT&CK and SOC KPIs.
Explored initial prompt chaining with LLMs (OpenAI GPT-3) to summarize detection reports for SOC interns, improving daily brief efficiency.
Onboarding logs in to Splunk 8.0.3 Version with using Forwarders, HEC, Syslog, DB connect and Custom Scripts.
Involved and worked on Splunk various components indexer, forwarder, search head, deployment server.
Migrated all ELK to Splunk cloud and helped all customer to understand Splunk search queries. Migrated all Kibana Alerts, Reports and Dashboards into Splunk.
Involved Troubleshoot Splunk onboarding issues, Monitor the Splunk Infrastructure for Capacity planning, Scalability and Optimization.
Implemented Cribl Stream pipelines to optimize observability data flow across cloud and on-prem environments, reducing Splunk ingestion costs by 30%.
Built data transformation and enrichment rules to normalize log formats, mask PII, and append contextual metadata for improved analytics.
Designed multi-destination routing strategies, sending high-value logs to Splunk while archiving raw data in S3 for compliance and long-term retention.
Configured Cribl Edge agents for distributed data collection across Kubernetes and Linux hosts, ensuring secure and scalable telemetry ingestion.
Managing and resolving complex security incidents, Incident responses and created detailed runbooks incorporating automated workflows, reducing manual effort and improving scalability for large-scale incidents
Authored and enhanced comprehensive playbooks for handling diverse security incidents, ensuring consistency and efficiency across IR teams
Created Splunk ITSI log Analytics artifacts Describing IEP services, Defining KPI’s and Configuration Thresholds.
Developed Splunk Dashboards, searches and reporting to support various internal clients in Security, IT Operations and Application Development.
Worked on ELK 6.8 version and Kibana 6.4.2 Versions. Migration and development the indexes under the ASV’s.
Wide Experience in Monitoring and troubleshooting the applications using tools like Grafana, solarwinds and App Dynamics
Managed and prioritize all work through tickets in JIRA Kanban platform and migrating all Kibana Dashboards, Reports and Alerts into Splunk and Meet the Documented Specifications
Integrated with Pager Duty for Splunk Alerts Validation of scope as outlined by Capital One for Saved searches, Alerts and Dashboards.
Install and Configured the Azure sentinel add-on. Also, Monitored and Created dashboards, Alerts.
Working on Integrate Tool Service Now. Creating Alerts and Building on Service Mapping for Connections between Various applications and Our Team Members
Created some of the alerts in Datadog and set up through PagerDuty and Email.
Experience in Creating and sending Risk Advisories to our client and Protecting Client data and Analyzed Security based Events, risks, and Reporting Events.
Worked on Operational Intelligence using Splunk and Creating Dashboards with the Using XML.
Divya Sri LLC Nov 2019 – Nov 2021
Splunk Operations Engineer
Responsibilities:
Onboard Responsible for Initiating, planning, executing, configuring, and deploying the latest version of Splunk on windows, Linux Environment.
Designed scalable backend services using Dockerized Python microservices to support secure log ingestion and cryptographic proof ingestion pipelines.
Implemented CI/CD pipelines for prover-related infrastructure using GitHub Actions and Jenkins, streamlining deployment across hybrid cloud environments.
Contributed to early-stage development of MPC-based key sharing for log encryption and ZK-based verification of log authenticity.
Integrated Splunk with Rust-based event processors that validated audit logs against blockchain-based proof-of-integrity ledgers.
Deployed Kubernetes workloads supporting distributed proof systems and implemented health-check APIs for prover node monitoring.
On boarding 9TB’s data from several components/Application logs in to Splunk, include the various IBM applications and database logs with using rsyslog, syslog-ng, DB connect, HEC, and Scripted inputs.
Onboarded 23 different types of data sources logs in to Splunk through various input methods include HEC and scripts.
Integrate Service Now with Splunk to consume the alerts from Splunk and create service now tickets. Experience with Splunk architecture and best practices.
Worked on both on-prem and cloud experience.
Strong experience on Troubleshooting Splunk search head, Indexer and forwarder issues and document.
Worked with ISAM and ISIM team to get onboard the various audit and user logsusing a syslog setup.
Install the SAI (Splunk App for Infrastructure) App to deploy the SCK (Splunk Kubernetes Cluster) with using Helm. Also, Configured HEC (HTTP Event Collector) to SAI.
Identify the malware threats and created the alerts for the DUO authentication request rejects.
Setup several KPIs for application performance, user activities and real-time alerting to get track of any abnormalizes across the infrastructure.
Working with Firewall Teams to Resolve the Security Threats and Creating the Alerts. Created many Security Dashboards with using XML Scripts.
Installed and worked on Splunk PaloAlto, AWS another Add-on’s.
Created and Managed Splunk DB connect Identities, Database Connections, Database Inputs, Outputs, lookups, access controls.
Worked on the Splunk ES notable issues and resolved various incident issues part of the regular health checks.
Created Notable events, KPI’s and Integrated multiple data sources into ITSI.
Worked on multiple ticketing tools like JIIRA, Service now and TFS
Education:
Masters in Data Science at University of North Texas, Denton, Texas, USA 2023
Bachelors in Information Technology from Institute of Aeronautical Engineering Hyderabad, Telangana, India. 2021