Post Job Free
Sign in

Cybersecurity Analyst - Cloud & SIEM Operations

Location:
Birmingham, AL
Posted:
October 03, 2026

Contact this candidate

Resume:

Lohitha Shavva

Email:- ****************@*****.*** URL:- www.linkedin.com/in/lohitha-shavva Ph:- +1-334-***-****

PROFESSIONAL SUMMARY

Cybersecurity Analyst with over 4 years of hands-on experience in Security Operations, Threat Detection, SIEM, Identity & Access Management (IAM), and Cloud Security (AWS, Azure).

Spearheaded real-time monitoring and triage of 10,000+ security events daily using Splunk and Microsoft Sentinel, resulting in 98% SLA adherence and 40% reduction in false positives.

Proficient in Cloud Security operations across AWS and Azure, with expertise in cloud-native tools like GuardDuty, CloudTrail, and Defender for Cloud, contributing to early threat detection and risk posture improvement.

Strong exposure to IAM platforms such as Okta, SailPoint, and Saviynt, leading secure provisioning and role-based access control across hybrid environments.

Applied MITRE ATT&CK, OWASP Top 10, and SANS CWE Top 25 frameworks to improve detection strategies, enhance threat modeling, and secure cloud-native applications via AppSec controls and DevSecOps pipelines.

Hands-on experience in automating detection and remediation workflows using Python, PowerShell, and Bash, accelerating response time and reducing analyst workload by 30%.

WORK EXPERIENCE

Optiv- Azure Cloud Security Operations Specialist Dec 2024 – present

Integrated SAST/DAST tools like SonarQube, OWASP ZAP, and Burp Suite into CI/CD pipelines, resulting in a 40% decrease in security flaws before production. Conducted OWASP Top 10 security assessments on custom applications and worked with developers to fix SQLi, XSS, and SSRF flaws early in the SDLC.

Automated cloud security scanning for Azure using custom Python and Terraform scripts, identifying misconfigurations, exposed APIs, and weak IAM policies. Developed PowerShell/Python-based scripts to automate patch verification and compliance audits, reducing manual effort by 50%.

Monitored cloud activity via Microsoft Sentinel, using KQL queries and custom analytics rules to detect anomalies in user behavior and resource access across subscriptions. Built automated playbooks using Azure Logic Apps and Sentinel SOAR integrations, streamlining response to common incidents such as brute-force login attempts, failed RDP access, and suspicious blob storage downloads.

Integrated OWASP Dependency-Check and Snyk for open-source software composition analysis, reducing vulnerable packages by 35%. Enforced input validation, authentication hardening, and secure session management aligned with OWASP and NIST guidelines

Cyient – SOC Engineer Feb 2021 - July 2023

Conducted security event triage and monitoring using Microsoft Sentinel, achieving an average threat detection time of 15 minutes and enhancing SOC efficiency. Created advanced correlation rules and detection use cases mapped to the MITRE ATT&CK framework, improving detection accuracy by 35%.

Deployed and managed Symantec Endpoint Protection (SEP) across 1,000+ endpoints, enhancing malware defense coverage. Integrated Cisco Umbrella as a secure DNS proxy, leading to a 25% reduction in phishing-related incidents.

Performed weekly vulnerability assessments using Nessus and Qualys, prioritizing remediation based on CVSS and threat intel. Executed internal penetration tests using Metasploit, achieving a 30% reduction in exploitable risks and validating remediation.

Performed deep-dive investigations on high-fidelity alerts, correlating logs across firewall, EDR, WAF, and proxy layers to validate threats, leveraging MITRE ATT&CK for TTP mapping and prioritization.

Worked on Tier-1 to Tier-2 escalations and coordinated with IR teams during critical incidents (malware outbreaks, phishing campaigns, insider threats), ensuring minimal business impact and rapid containment.

Developed SIEM detection rules and dashboards to identify brute-force, privilege misuse, data exfiltration, and lateral movement activity across hybrid cloud environments.

TECHNICAL SKILLS

SIEM & Log Analysis: Splunk, Microsoft Sentinel (Expert) Real-time threat detection, alert triage, custom rule creation, dashboard development.

Endpoint Protection: Symantec SEP, CrowdStrike Falcon (Advanced) Endpoint detection and response, malware mitigation, policy enforcement

Proxy & Web Filtering: Cisco Umbrella, Zscaler (Advanced) Web filtering, phishing protection, DNS security.

Identity & Access Management: SailPoint, Saviynt, Okta, MFA, SSO (Expert) Access controls, RBAC, privileged access management, IAM lifecycle.

Penetration Testing & AppSec: Metasploit, Burp Suite, OWASP Zap, Nikto, Wapiti (Advanced) Vulnerability exploitation, OWASP Top 10 mitigation, SAST/DAST integration.

Vulnerability Management: Tenable Nessus, Qualys, OpenVAS (Expert) Automated scanning, CVSS prioritization, patch management.

Email Security: Proofpoint TAP & TRAP (Advanced) Phishing protection, threat intel integration, email filtering.

Threat Intelligence (OSINT): VirusTotal, URLVoid, Cisco Talos, IBM X-Force (Advanced) IOC enrichment, threat feed correlation, threat hunting support.

Network Security Monitoring: Wireshark, Suricata, Network Flow Analyzers Advanced) Packet inspection, anomaly detection, network behavior analysis.

Intrusion Detection & Prevention: Snort, Suricata (Advanced) IDS/IPS deployment, signature tuning, false positive reduction.

Cloud Security: AWS, Azure Advanced) Cloud configuration audits, IAM policy enforcement, cloud-native security tools.

Malware Analysis: Ghidra, Cuckoo Sandbox (Intermediate) Static and dynamic analysis, IOC extraction.

Forensics & Incident Response: Autopsy, Volatility (Advanced) Incident investigation, memory forensics, evidence collection

EDUCATION & CERTIFICATION

Master of Science in Computer Science (AUM) Aug2023 – Dec 2024

Microsoft Certified: Azure AI Fundamentals Microsoft Certified: Azure Security Engineer Associate

Microsoft Certified: Security Operations Analyst Associate CompTIA Security+ Certification



Contact this candidate