Post Job Free
Sign in

Cyber Security Engineer - Incident Response & SIEM

Location:
Allen, TX
Salary:
90000
Posted:
October 05, 2026

Contact this candidate

Resume:

Prashanth J

Cyber Security Engineer

Allen, Texas *************@*****.*** +1-903-***-****

PROFESSIONAL SUMMARY

Cybersecurity Engineer with 4+ years of experience designing, implementing, and operating security controls and leading incident response across cloud and enterprise environments. Hands-on with SIEM platforms (Splunk, IBM QRadar), EDR, and SOAR automation, plus firewalls, AWS IAM, and Azure security services. Delivered 45+ SIEM correlation rules that reduced false positives by 35%, Phantom SOAR playbooks that cut mean time to respond (MTTR) by 40%, and threat hunting that uncovered 12 distinct cloud security anomalies. Develops security playbooks and procedures and collaborates with cross- functional teams.

TECHNICAL SKILLS

SIEM & Security Analytics: Splunk, IBM QRadar, Azure Monitor, Google Chronicle, Logstash, CRIBL Endpoint & Network Security: EDR, Firewalls, CrowdStrike Falcon, Zscaler, TCP/IP, DNS, Wireshark, Network Security Incident Response & Threat Hunting: Incident Response, Threat Hunting, Malware Investigation, Phishing Investigation, Credential Abuse Investigation, Containment & Remediation, Root Cause Analysis Security Automation & SOAR: SOAR Platforms, Phantom SOAR, Security Playbooks, Python, Bash Scripting, AWS Lambda, Alert Enrichment, Automated Response

Cloud & Identity Security: AWS IAM, Azure Security Center, AWS CloudTrail, AWS Config, Cloud Security, Identity & Access Management

Security Operations & Detection: Detection Engineering, Threat Detection, Detection Tuning, Security Monitoring, Alert Triage, MITRE ATT&CK, Threat Intelligence

Infrastructure & Security Tools: Terraform, Git, Security Logging, Telemetry Integration, Log Parsing, API Security PROFESSIONAL EXPERIENCE

Cyber Security Engineer — CrowdStrike Remote, USA April 2025 – Present

• Accelerated threat containment and remediation across enterprise endpoints and cloud platforms by leading cybersecurity incident response investigations in Google Chronicle and Splunk

• Reduced false positives by 35% by designing, developing, and tuning 45+ SIEM correlation rules and behavioral detections in Google Chronicle and Splunk

• Reduced mean time to respond (MTTR) by 40% by building and managing automated incident response playbooks in Phantom SOAR

• Cut analyst investigation time by 45% by automating incident response workflows with Phantom SOAR and Python to enrich security alerts with threat intelligence and orchestrate endpoint containment actions

• Drove rapid containment, forensic analysis, and root cause identification by investigating malware infections, phishing campaigns, insider threats, credential abuse, and lateral movement using SIEM, EDR telemetry, and threat intelligence

• Improved detection coverage for credential abuse, lateral movement, and privilege escalation by engineering threat detection use cases and behavioral analytics mapped to the MITRE ATT&CK framework

• Delivered enterprise-wide threat visibility by integrating, normalizing, and validating security telemetry from cloud, endpoint, and network sources using CRIBL and Logstash into Google Chronicle

• Accelerated incident investigations and surfaced advanced persistent threats (APTs) by developing Python-based threat hunting and detection automation scripts that analyze large-scale security telemetry

• Strengthened cross-team response readiness by partnering with SOC, engineering, and operations teams and documenting automated incident response playbooks

Cyber Security Engineer — AT&T Plano, Texas Jan 2024 – Mar 2025

• Improved telemetry coverage by 25% by spearheading high-priority threat hunting operations that uncovered 12 distinct cloud security anomalies

• Enabled immediate isolation of compromised assets and disabling of anomalous credentials by designing automated mitigation playbooks using Python and AWS Lambda

• Decreased manual search effort by 50% by developing automated threat hunting scripts in Python to analyze API access patterns and AWS CloudTrail logs

• Improved visibility into 5G core network activity by configuring and managing complex log integration pipelines for network telemetry into Splunk and Google Chronicle

• Turned threat intelligence into actionable SIEM alert configurations and detection tuning strategies by collaborating closely with security operations center (SOC) analysts Security Engineer — Airtel India Jun 2021 – July 2022

• Strengthened network security monitoring by performing log analysis and incident triaging across IBM QRadar SIEM and Splunk platforms

• Contained and remediated over 30 unauthorized system access attempts across critical production devices by executing incident response containment procedures

• Decreased recurring security alarm volume by 30% across key telecom segments by engineering custom detection signatures within SIEM platforms

• Supported continuous monitoring by maintaining and optimizing security log parsing templates using Python and Logstash configurations

• Streamlined handover coordination between operations tiers by documenting playbooks and standard operating procedures (SOPs) for incident escalation

EDUCATION

Master of Science in Information Technology Arkansas Tech University



Contact this candidate