Komal Marupalli
Email: *****************@*****.*** Tel: 519-***-****, Toronto
Linkedin: https://www.linkedin.com/in/komalmarupalli/
PROFESSIONAL SUMMARY
Cybersecurity Analyst with nearly 5 years of experience supporting Security Operations Center (SOC) environments, incident response, threat monitoring, and security investigations within enterprise environments. Experienced in triaging security alerts, conducting log analysis, assessing security risks, and supporting incident containment and remediation activities. Skilled in SIEM platforms, endpoint security tools, threat hunting, and incident documentation aligned with NIST and MITRE ATT&CK framework and TTPs. Recognized for strong analytical thinking, attention to detail, and the ability to communicate technical findings effectively with stakeholders.
SKILLS AND STRENGTHS
• Security Systems & Network Management:
SIEM (Qradar, Wazuh, Microsoft Sentinel), EDR/XDR (Microsoft Defender, Palo Alto, CrowdStrike), IDS/IPS (Suricata), Firewalls (Next-Generation Firewalls, NDR platforms, pfSense), Cloud Security (AWS, AWS IAM Policies, CloudTrail, S3 policies), Virtualization (Docker, Windows/Linux OS security baselining, Microsoft Azure Infrastructure – Intune, SCCM, Explorer, Endpoint, submissions, DLP, PAM
• Forensics and Malware Analysis:
Volatility, Magnet RAM Capture, Autopsy, Eric Zimmerman Tools, PE Studio, FLOSS, ProcMon, CFF Explorer, HashMyFiles, Magnet AXIOM, FTK Imager, Burp suit, Impacket.
• Threat Intelligence and Incident Response:
MITRE ATT&CK Framework, IOC Analysis Tools, OSINT Tools (Virus Total, any.run), Digital Forensics Tools (Autopsy, Volatility), Threat Hunting with Wazuh and Network Miner.
• Vulnerability Management and Penetration Testing:
Nessus, Qualys, Nmap, Metasploit, Kalilinux
• Programming and Scripting:
PowerShel, Bash, Python, Shell Scripting Tools (Vim, Nano), AI/ML
• Security Awareness, Protocols and Training:
GoPhish, Security Training Platforms (KnowBe4, Cybrary), Documentation Tools (Microsoft Office, Confluence, SharePoint), Threat landscape-PROXY, WAF, TCP/UDP
• Miscellaneous Tools:
CyberChef, Netcat, Network Miner, Wireshark, Snort, TCPDump, Microsoft Excel (for log analysis).
• Security Governance, Risk & Compliance: Regulatory compliance: SOC 2, ISO 27001, PCI DSS, GDPR, Security control framework management (NIST, CIS), Audit preparation, evidence collection, and CAPA development, Risk assessments, gap analysis, and risk treatment planning (FAIR, ISO 27005), Automation, Industrial Control System (ICS).
• Technical Proficiency: Encryption Techniques and Microsoft PKI infrastructure, Vulnerability assessments, penetration testing, and Threat risk assessment, Information Security Management Systems (ISMS) implementation and audit preparation
WORK HISTORY
CYBERSECURITY ANALYST - 03/2024-Present
Canadian Tire- Mississauga, Ontario, Canada
• Led the triage, containment, and resolution of multiple cybersecurity incidents involving malware, insider threats, and unauthorized access attempts.
• Conducted detailed log analysis using Qradar and Windows Event Viewer to identify lateral movement, persistence, and C2 activity.
• Integrated Microsoft Defender for Endpoint and Defender for Cloud Apps to improve threat visibility and data protection.
• Created and maintained playbooks for incident response including phishing, ransomware, and data leakage.
• Automated alert enrichment and incident workflows using SOAR platform to reduce response times by 40%.
• Delivered daily and weekly threat reports and KPI metrics to management and stakeholders.
• Conducted proactive threat hunting based on Threat Intelligence and applied MITRE ATT&CK and Cyber Kill Chain frameworks to identify attack patterns and map threat actor behavior.
• Performed security monitoring using Qradar, analyzing over 5,000 events daily, resulting in a 35% reduction in incident response time.
• Investigated malware infections and unauthorized access attempts, mitigating 20+ critical incidents and improving overall network security by 40%.
• Performed vulnerability assessments using Nessus, addressing 250+ vulnerabilities within 6 months to strengthen network security. Oversaw patch management, system hardening, and vulnerability remediation efforts, ensuring prompt updates and securing critical vulnerabilities.
• Fine-tuned detection rules, resulting in a 30% reduction in false-positive alerts and significantly improving SIEM efficiency.
• Executed digital forensics with tools like Magnet RAM Capture and Volatility, reconstructing attack timelines for over 10 incidents.
• Ensured compliance with SOC 1 & 2, PCI DSS, GDPR, HIPAA, and PIPEDA frameworks, conducting security audits and implementing controls to meet regulatory standards.
• Delivered training and mentorship to junior analysts on threat detection and escalation procedures.
• Executed root cause analysis and developed detailed incident reports for security breaches.
• Participated in Quarterly Service Reviews (QSRs) with the Customer Success Team to provide technical SOC input.
CYBERSECURITY ANALYST - 01/2022-12/2023
Fusion Computing Solutions - Toronto, Ontario, Canada
• Conducted security monitoring and incident response using advanced tools to detect and mitigate threats.
• Participated in enterprise-wide incident investigations, collaborating with legal, HR, and SOC teams for effective incident containment.
• Used SIEM and endpoint tools to conduct root cause analysis, identify attack vectors, and preserve evidence for forensics.
• Worked with Azure Security Center and DLP policies to monitor and prevent data exfiltration.
• Supported threat hunting initiatives using MITRE ATT&CK to detect anomalies and insider threats in the environment.
• Created documentation including incident reports, executive summaries, and lessons learned reports.
• Assessed and tested incident response capabilities against internal policies and NIST standards.
• Monitored network traffic using IDS/IPS tools, detecting and neutralizing 12 potential threats monthly.
• Delivered security awareness training to 50+ employees, reducing user-based vulnerabilities and improving cybersecurity practices.
• Designed and implemented security playbooks, cutting incident resolution time by 20%.
• Assisted in deploying Docker-based security tools (Qradar and Kibana), enhancing monitoring capabilities.
• Assisted in writing KB articles and training content to document incident response procedures.
EDUCATION
• Process Quality Engineering Post Graduation Diploma
Conestoga College, Kitchener
• Quality Assurance in Manufacturing and Management Post Graduation Diploma
Conestoga College, Kitchener
• Mechanical Engineering Bachelor of Technology
JNTUK College of Engineering, Kakinada, India
PROJECTS & ACHIEVEMENTS
CAPSTONE PROJECT
Project Name: Phishing Simulation Using GoPhish
Objective: Conducted phishing campaigns to evaluate user behavior and improve cybersecurity awareness.
• Developed and launched phishing simulation campaigns targeting various organizational roles.
• Analyzed user responses and identified high-risk groups for targeted awareness training.
• Resulted in a 30% improvement in phishing identification rates within the organization.
2) Project Name: Automated Threat Intelligence Enrichment: Developed scripts to integrate VirusTotal and AbuseIPDB APIs for IOC enrichment, reducing manual workload by 30%.
3) Project Name: Incident Response Metrics Dashboard: Created KPI dashboards in Power BI to report on incident volumes, MTTR, and threat categories for executive reporting.
4) Project Name: EDR Rule Tuning & False Positive Reduction: Tuned Defender XDR and Exabeam correlation rules to improve detection accuracy and reduce alert fatigue.
CERTIFICATIONS
• CompTIA Security+ (In Process)
• ISC2 Certified in Cybersecurity (In Process)
• Microsoft Certified: Security Operations Analyst Associate – Planned
• IBM Cybersecurity Analyst Professional Certificate - Planned