At Infosys, I respond to security alerts across SIEM, ATP/EDR, SOAR, and threat intelligence platforms within defined SLAs.
I investigate endpoint, identity, cloud, and email threats using Microsoft Defender, Microsoft Sentinel, Microsoft Entra, Microsoft Cloud App Security, Proofpoint, and Splunk. I apply MITRE ATT&CK and Cyber Kill Chain frameworks to analyze adversary tactics, improve detection logic, and reduce malware impact.
I analyze phishing, spam, suspicious payloads, malware, network traffic, firewall, IDS, and IPS alerts to validate threats and recommend mitigation actions.
I also document and escalate incidents through ServiceNow, perform root cause analysis on malware threats, enrich threat intelligence, and prepare daily, weekly, monthly, and ad-hoc security reports.
