Post Job Free
Sign in

Cybersecurity Engineer: SIEM, IR, Vulnerability Management

Location:
Jersey City, NJ
Posted:
October 03, 2026

Contact this candidate

Resume:

JAYADEEP BURUGU

CYBERSECURITY ENGINEER SECURITY OPERATIONS INCIDENT RESPONSE VULNERABILITY MANAGEMENT

Jersey City, New Jersey ****************@*****.*** +1-201-***-****

PROFESSIONAL SUMMARY

Cybersecurity professional with 2+ years of hands-on experience in enterprise security operations, SIEM monitoring, incident response, vulnerability management, endpoint security, threat detection, and security-control improvement. Experienced with Microsoft Sentinel, Splunk, IBM QRadar, Microsoft Defender, CrowdStrike, Nessus, Qualys, ServiceNow, KQL, SPL, QRadar AQL, Sentinel SOAR, Logic Apps, Azure Log Analytics, and Wireshark. Skilled in investigating endpoint, network, cloud, and identity telemetry; supporting P1/P2 incident response; prioritizing vulnerabilities using CVE and threat context; tuning detections; coordinating containment and remediation; and maintaining security runbooks and evidence. Working knowledge of AWS/Azure security concepts, IAM and identity telemetry, Zero Trust principles, NIST SP 800-61, MITRE ATT&CK, ISO 27001, SOC 2, and Cyber Kill Chain.

CORE TECHNICAL SKILLS

Security Engineering: Security Controls, Endpoint Protection, Network Security, Security Monitoring, Security Tool Support, Security Reviews, Security Documentation

SIEM: Microsoft Sentinel, Splunk, IBM QRadar, Azure Log Analytics, Syslog, Log Source Analysis

EDR / Endpoint: Microsoft Defender for Endpoint and Cloud, CrowdStrike, Endpoint Telemetry, Host Investigation, Containment Coordination

Incident Response: Incident Detection, Alert Triage, P1/P2 Response, Evidence Collection, Timeline Reconstruction, Root-Cause Analysis, Containment, Recovery Support

Vulnerability Management: Nessus, Qualys, CVE Analysis, Vulnerability Scanning, Risk-Based Prioritization, Remediation Tracking, Configuration Weakness Review

Threat Detection: KQL, SPL, QRadar AQL, Threat Hunting, Detection Engineering, Analytics Rules, Correlation Rules, IOC Analysis, MITRE ATT&CK

Security Automation: Microsoft Sentinel SOAR, Logic Apps, IOC Enrichment, Automated Lookups, Ticket Creation, Workflow Automation

Cloud / Identity: Azure, AWS, Cloud Security Monitoring, Identity Telemetry, Authentication Analysis, Privilege Escalation Detection, IAM Concepts

Governance / Frameworks: NIST SP 800-61, ISO 27001, SOC 2, Cyber Kill Chain, Security Procedures, Runbooks, Audit Evidence

PROFESSIONAL EXPERIENCE

SOC Analyst Zelis Dec 2025 – Present

• Monitor, triage, and investigate security events in Microsoft Sentinel and Splunk within a 24x7 SOC, correlating endpoint, network, Azure/AWS cloud, and identity telemetry to identify threats and potential security incidents.

• Investigate anomalous authentication, privilege-escalation indicators, lateral movement, phishing, malware-related activity, suspicious network behavior, and indicators of compromise using KQL queries, analytics rules, and Sentinel workbooks.

• Support P1/P2 incident response by validating evidence, reconstructing timelines, documenting findings and root-cause analysis in ServiceNow, mapping activity to MITRE ATT&CK, and escalating high-impact cases through established response procedures.

• Coordinate with endpoint/EDR, network security, infrastructure, threat intelligence, and vulnerability-management teams to validate containment, coordinate host isolation/remediation, and improve security response readiness.

• Review Nessus vulnerability findings and correlate exploitable CVEs with active security alerts and threat-intelligence context to support risk-based prioritization and remediation follow-up.

• Use Qualys and vulnerability-management workflows to support security finding review, remediation coordination, and tracking of identified weaknesses with relevant technical teams.

• Tune KQL analytics and hunting queries to improve detection quality, strengthen security visibility, and reduce false-positive alert noise.

• Use Microsoft Sentinel SOAR playbooks and Logic Apps to automate repeatable IOC enrichment, indicator lookups, and ticket-creation workflows, reducing manual investigation effort and improving operational consistency.

• Maintain incident documentation, security runbooks, operational handoffs, and audit evidence supporting SOC 2 and ISO 27001 activities.

Junior SOC Analyst Bridge Soft Solutions Feb 2023 – Nov 2024

• Monitored and analyzed security events in Splunk and IBM QRadar across firewall, IDS/IPS, endpoint, and cloud log sources in a shift-based SOC environment.

• Investigated phishing, malware, brute-force authentication attempts, suspicious network activity, and other security events; documented evidence and escalated incidents according to established response procedures.

• Performed SIEM investigations using SPL and QRadar AQL, correlating events across multiple log sources and tuning correlation rules to improve detection quality and reduce unnecessary alerts.

• Reviewed Nessus vulnerability scan results for exposed assets, missing patches, and configuration weaknesses; documented findings and supported remediation follow-up with technical teams.

• Supported incident identification, analysis, escalation, response coordination, and post-incident documentation using the NIST SP 800-61 incident-response lifecycle.

• Maintained SOC runbooks, investigation records, knowledge articles, and shift-handover documentation to support consistent security operations.

EDUCATION

• Master of Science, Computer and Information Systems Adelphi University 2026

• B.Tech, Computer Science Engineering (Artificial Intelligence & Machine Learning) B V Raju Institute of Technology

CERTIFICATION

• Splunk Core Certified User

RELEVANT SECURITY KNOWLEDGE

• IAM and Zero Trust: authentication, authorization, least-privilege concepts, identity telemetry, anomalous sign-in analysis, privilege escalation indicators, and layered security controls.

• Cloud Security: security monitoring and investigation across Azure and AWS telemetry; cloud identity, endpoint, network, and logging concepts.

• Compliance & Security Frameworks: NIST SP 800-61, ISO 27001, SOC 2 evidence support, MITRE ATT&CK, and Cyber Kill Chain.

• Security Operations Improvement: detection tuning, false-positive reduction, SOAR automation, runbook development, incident documentation, and cross-functional remediation.



Contact this candidate