Prashanth J
Cyber Security Engineer
Allen, Texas *************@*****.*** +1-903-***-****
PROFESSIONAL SUMMARY
Cybersecurity Engineer with 4+ years of experience designing, implementing, and operating security controls and leading incident response across cloud and enterprise environments. Hands-on with SIEM platforms (Splunk, IBM QRadar), EDR, and SOAR automation, plus firewalls, AWS IAM, and Azure security services. Delivered 45+ SIEM correlation rules that reduced false positives by 35%, Phantom SOAR playbooks that cut mean time to respond (MTTR) by 40%, and threat hunting that uncovered 12 distinct cloud security anomalies. Develops security playbooks and procedures and collaborates with cross- functional teams.
TECHNICAL SKILLS
SIEM & Security Analytics: Splunk, IBM QRadar, Azure Monitor, Google Chronicle, Logstash, CRIBL Endpoint & Network Security: EDR, Firewalls, CrowdStrike Falcon, Zscaler, TCP/IP, DNS, Wireshark, Network Security Incident Response & Threat Hunting: Incident Response, Threat Hunting, Malware Investigation, Phishing Investigation, Credential Abuse Investigation, Containment & Remediation, Root Cause Analysis Security Automation & SOAR: SOAR Platforms, Phantom SOAR, Security Playbooks, Python, Bash Scripting, AWS Lambda, Alert Enrichment, Automated Response
Cloud & Identity Security: AWS IAM, Azure Security Center, AWS CloudTrail, AWS Config, Cloud Security, Identity & Access Management
Security Operations & Detection: Detection Engineering, Threat Detection, Detection Tuning, Security Monitoring, Alert Triage, MITRE ATT&CK, Threat Intelligence
Infrastructure & Security Tools: Terraform, Git, Security Logging, Telemetry Integration, Log Parsing, API Security PROFESSIONAL EXPERIENCE
Cyber Security Engineer — CrowdStrike Remote, USA April 2025 – Present
• Accelerated threat containment and remediation across enterprise endpoints and cloud platforms by leading cybersecurity incident response investigations in Google Chronicle and Splunk
• Reduced false positives by 35% by designing, developing, and tuning 45+ SIEM correlation rules and behavioral detections in Google Chronicle and Splunk
• Reduced mean time to respond (MTTR) by 40% by building and managing automated incident response playbooks in Phantom SOAR
• Cut analyst investigation time by 45% by automating incident response workflows with Phantom SOAR and Python to enrich security alerts with threat intelligence and orchestrate endpoint containment actions
• Drove rapid containment, forensic analysis, and root cause identification by investigating malware infections, phishing campaigns, insider threats, credential abuse, and lateral movement using SIEM, EDR telemetry, and threat intelligence
• Improved detection coverage for credential abuse, lateral movement, and privilege escalation by engineering threat detection use cases and behavioral analytics mapped to the MITRE ATT&CK framework
• Delivered enterprise-wide threat visibility by integrating, normalizing, and validating security telemetry from cloud, endpoint, and network sources using CRIBL and Logstash into Google Chronicle
• Accelerated incident investigations and surfaced advanced persistent threats (APTs) by developing Python-based threat hunting and detection automation scripts that analyze large-scale security telemetry
• Strengthened cross-team response readiness by partnering with SOC, engineering, and operations teams and documenting automated incident response playbooks
Cyber Security Engineer — AT&T Plano, Texas Jan 2024 – Mar 2025
• Improved telemetry coverage by 25% by spearheading high-priority threat hunting operations that uncovered 12 distinct cloud security anomalies
• Enabled immediate isolation of compromised assets and disabling of anomalous credentials by designing automated mitigation playbooks using Python and AWS Lambda
• Decreased manual search effort by 50% by developing automated threat hunting scripts in Python to analyze API access patterns and AWS CloudTrail logs
• Improved visibility into 5G core network activity by configuring and managing complex log integration pipelines for network telemetry into Splunk and Google Chronicle
• Turned threat intelligence into actionable SIEM alert configurations and detection tuning strategies by collaborating closely with security operations center (SOC) analysts Security Engineer — Airtel India Jun 2021 – July 2022
• Strengthened network security monitoring by performing log analysis and incident triaging across IBM QRadar SIEM and Splunk platforms
• Contained and remediated over 30 unauthorized system access attempts across critical production devices by executing incident response containment procedures
• Decreased recurring security alarm volume by 30% across key telecom segments by engineering custom detection signatures within SIEM platforms
• Supported continuous monitoring by maintaining and optimizing security log parsing templates using Python and Logstash configurations
• Streamlined handover coordination between operations tiers by documenting playbooks and standard operating procedures (SOPs) for incident escalation
EDUCATION
Master of Science in Information Technology Arkansas Tech University