Post Job Free
Sign in

Cybersecurity Analyst - SIEM/EDR Incident Response

Location:
Little Elm, TX
Salary:
I would be comfortable with a salary range of $120
Posted:
October 05, 2026

Contact this candidate

Resume:

Narender Kanchi

Narender-kanchi ********.*****@*****.*** +1-940-***-****

SUMMARY:

●Cybersecurity Analyst with 9+ years of experience in Security Operations, Incident Response, Threat Hunting, Detection Engineering, Vulnerability Management, and Security Monitoring across enterprise environments.

●Hands-on expertise in SIEM, EDR, and SOAR platforms including Microsoft Sentinel, Splunk Enterprise Security, CrowdStrike Falcon, Microsoft Defender XDR, and Cortex XSOAR for threat detection, investigation, and automated response.

●Skilled in malware analysis, phishing investigations, insider threat detection, IOC analysis, threat intelligence integration, MITRE ATT&CK mapping, and advanced threat detection to identify and mitigate cyber risks.

●Strong experience analyzing network traffic, endpoint telemetry, cloud logs, and security events across TCP/IP, DNS, HTTP/S, SMTP, cloud, and hybrid environments to detect indicators of compromise and malicious activity.

●Proficient in developing and tuning SIEM correlation rules, security use cases, detection content, and security analytics to improve visibility, reduce false positives, and strengthen threat detection capabilities.

●Experienced in supporting the full incident response lifecycle, including alert triage, investigation, containment, eradication, recovery, root cause analysis, and post-incident reporting for critical security incidents.

●Hands-on experience supporting P1/P2 incident response, threat hunting, root cause analysis, containment, eradication, and recovery activities.

●Extensive knowledge of cybersecurity frameworks and standards including NIST CSF, NIST 800-53, ISO 27001, MITRE ATT&CK, Cyber Kill Chain, and security governance best practices.

●Strong background in Data Loss Prevention (DLP), email security, endpoint security, vulnerability management, cloud security monitoring, and security control validation across enterprise environments.

●Proven ability to leverage threat intelligence, security metrics, operational reporting, and risk assessments to improve security posture, support compliance initiatives, and reduce organizational risk.

●Effective collaborator with SOC, CSIRT, Threat Intelligence, Engineering, Risk, Compliance, and business stakeholders, translating complex technical findings into actionable recommendations for both technical and non-technical audiences.

●Led knowledge-sharing and mentorship initiatives for junior SOC analysts, developing expertise in SIEM operations, threat detection, incident investigations, and response procedures while improving team efficiency and operational maturity.

●Certified Information Security Manager (CISM), Certified Ethical Hacker (CEH v13), and Certified SOC Analyst with a track record of enhancing cyber resilience, operational efficiency, and security program maturity.

AREAS OF EXPERTISE:

SOC Operations Incident Response Threat Hunting Threat Detection & Response Security Monitoring SIEM (Splunk, Microsoft Sentinel, QRadar, Chronicle) Detection Engineering Security Analytics Threat Intelligence IOC Analysis Malware Analysis Phishing Analysis EDR/XDR Operations CrowdStrike Falcon Microsoft Defender XDR SOAR Automation DLP & Data Protection Insider Threat Monitoring Vulnerability Management Log Analysis Event Correlation Network Security Email Security Cloud Security Monitoring MITRE ATT&CK Root Cause Analysis (RCA) Risk Assessment Security Governance Compliance & Audit Support Security Reporting & Metrics Security Awareness Training Security Operations Leadership

SECURITY CERTIFICATIONS:

●Certified Information Security Manager (CISM) – ISACA

●Certified Ethical Hacker (CEH v13) – EC-Council

●Certified SOC Analyst – EC-Council

AWARDS:

●Stellar Orion Award – Commitment & Accountability

●Superlative Teammate Award – Performance & Contribution

EDUCATION:

Bachelor’s Degree - Gokaraju Ranga Raju Institute of Engineering & Technology

Graduated in December 2016

TECHNICAL SKILLS:

●SIEM & Security Operations: Splunk Enterprise Security, Microsoft Sentinel, Google Chronicle, IBM QRadar, ArcSight, SOC Operations, Security Monitoring, Alert Triage, Event Correlation, Detection Engineering, Threat Hunting, Elastic Security, Kibana, Incident Response, Malware Analysis, Phishing Analysis, IOC Analysis, Root Cause Analysis (RCA), CSIRT Operations.

●Threat Intelligence & OSINT: Recorded Future, ThreatConnect, Virus Total, Shodan, Maltego, WHOIS, Threat Intelligence, Threat Enrichment, MITRE ATT&CK, DNS Analysis, IP & Domain Reputation Analysis.

●Security Automation & SOAR: Cortex XSOAR, SOAR Automation, Python, PowerShell, Bash, REST APIs, JSON, Playbook Development, Automated Incident Response.

●Data Protection & Email Security: Microsoft Purview, Symantec DLP, Data Classification, Insider Threat Monitoring, Data Governance, Proofpoint, Cisco IronPort, SPF, DKIM, DMARC, Email Threat Protection.

●EDR/XDR: CrowdStrike Falcon, Microsoft Defender for Endpoint, Tanium, Trellix, Symantec Endpoint Protection, McAfee, EDR, XDR, Endpoint Security Monitoring.

●Firewalls/IDS/IPS: Palo Alto, Cisco ASA, Cisco IronPort (ESA/WSA), Fortinet, Snort IDS/IPS, FireEye, WAF, Akamai, Cloudflare.

●Network Security: Palo Alto Networks, Check Point, Cisco ASA, Fortinet, Snort IDS/IPS, WAF, Akamai, Cloudflare, TCP/IP, DNS, HTTP/S, SMTP, SSL/TLS, VPN.

●Vulnerability Management & Compliance: Vulnerability Assessment, Vulnerability Remediation, Risk Assessment, NIST 800-53, NIST CSF, ISO 27001, SOX, Cyber Kill Chain, Security Governance, Audit Readiness.

●Cloud Security & ITSM: Cloud Security Monitoring, Cloud Threat Detection, Security Architecture, ServiceNow, Incident Management, Case Management, Security Reporting, KPI Reporting.

PROFESSIONAL EXPERIENCE:

Company: BNP Paribas - Dallas, TX Oct 2022 - Present

Project: Global Security Operations Centre

Role: Consultant Information Security Analyst

RESPONSIBILITIES:

●Perform real-time monitoring and triage of 300–600 weekly alerts in SIEM platforms, prioritizing events based on severity, threat context, and SLA requirements, maintaining >95% SLA adherence

●Investigate 10–20 security alerts per shift across malware, phishing, and suspicious activity using endpoint, network, and email telemetry, contributing to ~20% faster incident escalation

●Analyze logs and packet data (TCP/IP, DNS, HTTP/S, SMTP), reviewing GBs of daily log data to identify anomalies such as failed logins, suspicious traffic, and potential C2 activity

●Support development and tuning of 50+ SIEM rules/use cases mapped to MITRE ATT&CK, helping reduce false positives by 15–20%

●Handle P1/P2 incidents (5–10 per week) by performing initial triage, enrichment, and escalation to L3 teams within defined SLA timelines

●Investigate endpoint alerts across 500+ endpoints using EDR tools like CrowdStrike Falcon and Microsoft Defender, improving visibility into endpoint threats

●Monitor security events across 10–20 log sources (firewalls, endpoints, cloud logs), enhancing detection coverage and situational awareness

●Execute and support SOAR playbooks (10–15 use cases) for alert enrichment and basic response actions, reducing manual effort by ~25%

●Utilize Elastic Security (ELK Stack) for security monitoring, threat hunting, detection engineering, and log analytics across 10TB+ daily log ingestion environments, improving threat detection accuracy by 40% and reducing false positives by 30%

●Monitor DDoS events and conduct readiness assessments and mitigation testing using Cloudflare, Akamai, Radware, and SIEM platforms, improving attack detection, response effectiveness, and network resilience by 35–40% across 100+ applications and services

●Correlate and analyze logs from 10+ security controls (firewalls, IDS/IPS, WAF, proxies, AV) including Palo Alto, Cisco, and Check Point to identify suspicious patterns and improve threat detection accuracy by ~25%

●Manage Cisco Email Security Appliance (ESA) policies including anti-spam, anti-malware, email authentication (SPF, DKIM, DMARC), quarantine management, and secure email delivery

●Support investigations of 1000+ suspicious emails monthly through header analysis, URL inspection, and threat validation.

●Assist in vulnerability tracking by monitoring 100–200 vulnerabilities/month, validating patch status, and escalating critical findings

●Follow SOC runbooks and SOPs aligned with NIST/ISO standards, ensuring consistent incident handling and audit readiness

●Document and report 100% of incidents in ticketing systems, generating detailed investigation reports for stakeholders and escalation

●Collaborate with CSIRT and Threat Intelligence teams to validate 1,000+ IOCs, improving detection logic and reducing false negatives

●Develop executive dashboards and KPI reporting for 500+ monthly security incidents and vulnerabilities, improving visibility into detection effectiveness, SLA compliance, and operational performance by 30%

●Conduct security awareness training and phishing simulation programs for 500+ users, improving security policy compliance and reducing user-driven security risks by 25%

Environment/Tools: Splunk ES, Microsoft Sentinel, CrowdStrike Falcon, Microsoft Defender, Proofpoint, Cisco IronPort, Palo Alto, Check Point, IDS/IPS, WAF, SOAR, MITRE ATT&CK, Threat Hunting, Incident Response, IOC Analysis, CSIRT, Vulnerability Management, Security Monitoring, Security Operations Center (SOC), SIEM, Threat Intelligence, Phishing Analysis, Malware Analysis, DNS Analysis, Network Security, Cloud Security Monitoring, Security Automation, NIST, ISO 27001, SLA Management, Security Investigations, Endpoint Security, Log Analysis, Detection Engineering.

Company: Zalaris May 2019 - Oct 2022

Project: Security Monitoring and Operations

Role: Security Associate

RESPONSIBILITIES:

●Designed and tuned 15+ SIEM correlation rules and alerting use cases, improving detection accuracy and reducing false positives by 20%.

●Integrated and analyzed threat intelligence feeds from Recorded Future, Virus Total, and Shodan, enriching 1,000+ alerts monthly and proactively identifying malicious infrastructure.

●Supported SIEM and endpoint security architecture enhancements by integrating multiple EDR and log sources, improving security visibility and detection coverage across enterprise environments.

●Monitored and triaged security alerts in a 24x7 SOC using Splunk Enterprise Security, IDS/IPS, firewalls, and endpoint security tools, analyzing 500+ events monthly while maintaining 100% SLA adherence.

●Conducted log analysis across 100+ network and endpoint data sources, accelerating threat detection, incident escalation, and response activities.

●Conducted advanced incident investigations and root cause analysis, reducing recurring security incidents by 30% through improved detection and response strategies.

●Collaborated with cross-functional teams during P1/P2 security incidents, improving response coordination and minimizing business impact.

●Implemented and optimized DLP controls across email, endpoint, and cloud environments, reducing data exposure risks by 20% and strengthening policy effectiveness.

●Performed data classification validation and data flow analysis across 100+ sensitive data assets, enhancing protection of regulated and business-critical information.

●Managed 50+ DLP policy exceptions monthly, conducted access reviews, and facilitated risk acceptance processes, improving governance compliance and reducing unauthorized access risks.

●Supported vulnerability management initiatives by tracking 100+ remediation activities monthly, reducing exposure to critical vulnerabilities by 25%.

●Acted as a technical SME for SIEM and endpoint security platforms, mentoring L1 analysts and reducing escalation dependency by 20%.

●Contributed to SOC process improvements and detection engineering initiatives, increasing overall threat visibility by 20% and enhancing operational effectiveness.

●Developed weekly and monthly security metrics and operational reports, improving visibility into threat trends, control effectiveness, and SOC performance by 15%.

●Translated complex security findings into actionable recommendations for technical and business stakeholders, supporting risk reduction and informed decision-making.

Environment/Tools: Splunk Enterprise Security, SIEM, EDR, DLP, Threat Intelligence, Recorded Future, Virus Total, Shodan, Incident Response, Detection Engineering, Security Monitoring, SOC Operations, Vulnerability Management, Root Cause Analysis, Security Analytics, Data Classification, Data Governance, Access Reviews, Security Architecture, Endpoint Security, IDS/IPS, Firewall Security, Threat Detection, IOC Analysis, SLA Management, Security Reporting, Governance, Risk Management, Regulatory Compliance.

Company: Daicenet Solutions Pvt Ltd, Mar 2017 - May 2019

Project: Security Monitoring and Operations

Role: Cyber Security Analyst

RESPONSIBILITIES:

●Created and optimized 10+ Splunk SPL queries, dashboards, and alerts, improving early threat detection capabilities and reducing alert noise by 20%.

●Leveraged SIEM, HIPS, proxy, and vulnerability management technologies to support security monitoring and incident investigations, contributing to faster threat identification and improved operational efficiency.

●Monitored 24x7 SOC operations across network devices, firewalls, IDS/IPS, and antivirus solutions, analyzing 100+ security events weekly to identify anomalies and ensure timely escalation of security incidents.

●Collected and analyzed logs from 50+ infrastructure and endpoint sources, enhancing threat visibility and contributing to a 25% improvement in incident response times.

●Performed second-level incident investigations, managing 50+ security cases monthly while maintaining 98% SLA adherence for incident resolution and escalation.

●Investigated 20–30 security incidents monthly, applied mitigation strategies, and prepared root cause analysis reports, improving SOC operational efficiency by 20%.

●Supported investigations of 100+ suspicious emails monthly through header analysis, URL inspection, and threat validation to identify phishing attempts and malicious activity.

●Analyzed hundreds of email security events using Proofpoint, improving phishing detection accuracy and strengthening enterprise email threat protection capabilities.

●Deployed and managed DLP controls across endpoints and email channels, reducing potential data leakage risks by 15% and improving protection of sensitive information.

●Developed security dashboards and operational reports that enhanced visibility into organizational security posture, supported audit readiness initiatives, and improved management reporting effectiveness.

●Collaborated with cross-functional teams to communicate security findings, remediation recommendations, and operational metrics, supporting informed decision-making and continuous security improvement.

Environment/Tools: Splunk Enterprise Security, Splunk SPL, SIEM, SOC Operations, Security Monitoring, Incident Response, Incident Investigation, Root Cause Analysis, Threat Detection, Threat Analysis, Detection Engineering, Security Analytics, Alert Triage, Log Analysis, Event Correlation, IDS/IPS, Firewall Security, Endpoint Security, Proofpoint, Email Security, Phishing Analysis, URL Analysis, DLP, Data Protection, Data Leakage Prevention, Vulnerability Assessment, HIPS, Antivirus, Security Reporting, Audit Readiness, SLA Management, Security Operations, Infrastructure Security, Threat Investigation.



Contact this candidate