SAI AISHWARYA NAMAVARAPU
Security Engineer Detection Engineering & SOC Cloud Security
San Jose, CA • 408-***-**** • ************@*********.*** • linkedin.com/in/sai-aishwarya-3243b8215 • github.com/Saiber239 SUMMARY
Security Engineer with 3+ years in SOC operations, detection engineering, incident response, and cloud security. Builds and tunes detection logic in Splunk ES and Microsoft Sentinel, automates triage and response with Python, KQL, and SOAR playbooks, and hardens Azure and Entra ID against NIST CSF and CIS Benchmarks.
TECHNICAL SKILLS
SIEM & Detection Engineering: Splunk Enterprise Security (SPL), Microsoft Sentinel (KQL), Sigma, Detection-as-Code, correlation rule tuning, alert triage, threat hunting
Incident Response & Frameworks: Full IR lifecycle, root cause analysis, MITRE ATT&CK and ATLAS, NIST CSF, ISO 27001, CIS Benchmarks, OWASP Top 10, threat intelligence, ServiceNow
Endpoint, Identity & Cloud: CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, EDR investigation and containment, Microsoft Entra ID, IAM, MFA, Conditional Access, PAM, Azure and AWS Security, Nessus, Qualys, CVE triage Automation & Scripting: Python, PowerShell, Cortex XSOAR, Azure Logic Apps, GitHub Actions, CI/CD, REST APIs Network, Systems & AI Security: Wireshark, Suricata, TCP/IP, traffic analysis, Windows and Linux security, Sysmon, Active Directory, LLM security, prompt injection detection, LangChain
PROFESSIONAL EXPERIENCE
Cybersecurity Engineer DXC Technology — California, USA Jul 2025 – Present
• Engineer and tune detection content across Splunk ES and Microsoft Sentinel, authoring 40+ MITRE ATT&CK-mapped analytics rules that raised alert fidelity ~25% and cut recurring false positives on the highest-volume alert sources.
• Built a Detection-as-Code pipeline with Sigma, KQL, GitHub Actions, and CI/CD that version-controls and auto-validates detection rules, cutting rule deployment from several days to under an hour and stopping untested rules reaching production.
• Automated Tier-1 triage with Cortex XSOAR and KQL playbooks for phishing, malware, and impossible-travel alerts, removing 2+ hours of manual analyst work per day and driving a 33% reduction in mean time to respond.
• Developed Python tooling to audit endpoint logging config and validate agent health across the Windows estate, lifting Sysmon telemetry coverage from ~60% to 90%+ and closing visibility gaps in three ATT&CK tactics.
• Lead response on escalated incidents including credential compromise, malware, and suspicious cloud identity activity, performing root cause analysis and converting findings into new detections and playbook updates.
• Harden Azure and Microsoft Entra ID against CIS Benchmarks and NIST CSF, remediating misconfigurations in Conditional Access, privileged role assignment, and public storage exposure. Security Analyst (SOC) Siemens — India Mar 2022 – Jul 2023
• Triaged 50+ alerts per day in a 24x7 SOC using Splunk Enterprise Security and Microsoft Sentinel, escalating validated true positives with full investigative context and meeting response-time SLAs at 95% compliance.
• Investigated SentinelOne EDR detections end to end, independently resolving ~80% of cases and coordinating host isolation, containment, and remediation with infrastructure teams on confirmed threats.
• Wrote SPL and KQL queries across a dual-SIEM environment to correlate endpoint, identity, and network telemetry, building complete incident timelines and reducing investigation time on complex cases by ~40%.
• Owned incidents through the full lifecycle (detection, analysis, containment, eradication, closure) and documented 100% of cases in ServiceNow, sustaining audit readiness with zero documentation findings. Information Security Intern Avanti Group — India Feb 2021 – Jan 2022
• Supported risk assessments across 5+ business units, documenting 10+ control gaps mapped to NIST CSF and ISO 27001, and ran Nessus vulnerability scans with CVSS-prioritized findings reports for the security engineering team.
• Monitored SIEM alerts, escalated validated incidents to senior analysts, and documented tabletop exercise findings that fed into IR playbook updates.
PROJECTS
AI Guardian — Autonomous AI Agent Security Monitoring Framework Python, LLM Security, LangChain, MITRE ATLAS
• Built a framework detecting prompt injection, data leakage, and malicious tool execution against autonomous LLM agents, with 91% detection accuracy across 200+ simulated attack scenarios.
• Added behavioral baselining and anomaly detection to flag abnormal agent activity, producing risk scores and MITRE ATLAS-mapped response recommendations that cut manual analysis effort ~40%. Automated SIEM Detection & Response Pipeline Microsoft Sentinel, Azure Logic Apps, Python, KQL
• Built an end-to-end Sentinel pipeline with custom KQL detection rules and integrated threat intelligence enrichment, cutting manual alert triage 30% and false positives 20%.
• Added Azure Logic Apps remediation workflows that auto-remediate recurring cloud misconfigurations without analyst involvement, reducing incident response time 25% on those findings. EDUCATION & CERTIFICATIONS
M.S., Cybersecurity Syracuse University, Syracuse, NY, USA Aug 2023 – May 2025 Certifications: CompTIA Security+ • CompTIA Network+ • Microsoft Azure Fundamentals (AZ-900)