At Tata Consultancy Services (TCS), I triage and investigate security alerts in Sentinel and QRadar, identifying true positives and tuning detections to reduce false positives by 30%.
I handle investigations into phishing, malware, suspicious logins, and brute-force attacks. For more than 100 incidents per quarter, I determine scope and indicators of compromise and guide remediation.
I use Microsoft Entra ID to contain compromised accounts and Microsoft Defender to investigate endpoints, initiate scans, and isolate impacted devices. I also maintain block lists and write KQL queries and analytic rules.
I document incident timelines in ServiceNow, perform SIEM health checks, and apply MITRE ATT&CK mapping in investigations. I coordinate remediation with partner teams and provide incident updates and guidance.

