At Infosys, I integrated Defender for Endpoint with Microsoft Sentinel to centralize alert management and automate remediation workflows. I also built and maintained incident response playbooks using Azure Logic Apps for alert triage, ticket creation, and email notifications.
I investigated Defender alerts and phishing reports, performed root cause analysis, and documented incident findings and resolutions. I used KQL and SPL to create and fine-tune detection rules, and analyzed device timelines through advanced hunting.
I created security control implementation statements for Defender firewall policies, endpoint protections, and device exceptions. I also onboarded and trained weekend analysts on Defender telemetry, KQL queries, and threat-hunting practices.

