YASWANTH BOLISETTI

SENIOR SOC ANALYST

Senior SOC Analyst with 6+ years of experience in enterprise Security Operations, Incident Response, Threat Detection, Detection Engineering, Threat Hunting, phishing/BEC investigations and vulnerability management. Skilled in investigating incidents across endpoint, network, email, and SIEM telemetry; reconstructing attack chains; performing containment, eradication, root-cause analysis; and developing detection logic aligned to MITRE ATT&CK. Proficient with tools such as SentinelOne, Microsoft Sentinel, Kibana, IBM QRadar, CrowdStrike, Proofpoint and Microsoft 365. Seeking to leverage expertise in security operations and incident response for opportunities in Poland.

0
Language
0
Skills
0
Certification
Work Experience
Senior Security Associate
GARMIN
Feb 2024 — PresentCurrentHyderabad, India
  • Monitor and investigate enterprise security incidents using SentinelOne EDR, performing endpoint detection, threat containment and incident response
  • Develop and maintain S1QL and KQL dashboards for alert triage, egress anomaly detection, interpreter abuse and LOLBIN activity
  • Reconstruct attack chains including malvertising → ClickFix → SOCKS5 proxy C2 and perform root-cause analysis to identify initial compromise
  • Conduct endpoint forensic investigations using EVTX, Registry Hives, MFT, USN Journal, Prefetch and Shellbags to identify persistence and anti-forensics
  • Execute incident response using the SANS Incident Response Framework across identification, containment, eradication, recovery and lessons learned
  • Perform hypothesis-driven threat hunting for SSH tunneling, BYOVD, PowerShell abuse, command-line interpreters and LOLBIN techniques using custom S1QL queries
  • Author, tune and optimize detections for ClickFix, DSE/BCDEdit tampering, LLM-related egress and endpoint attack techniques
  • Collaborate with Purple Team exercises to validate detection coverage, map MITRE ATT&CK; techniques and identify detection gaps
  • Investigate Firewall, WAF, Proxy, DNS, Load Balancer and SIEM logs to trace attacker activity, validate C2 communications and distinguish genuine attacks from scanner noise
  • Investigate phishing, Business Email Compromise and vendor email compromise using Microsoft 365 and Proofpoint TAP/TRAP, including headers, SPF, DKIM, DMARC, malicious URLs and attachments
  • Respond to P1 incidents including ransomware, lateral movement, credential compromise and endpoint intrusions; create SOC playbooks and standardized response procedures
Security Analyst
COFORGE
Sep 2020 — Jan 2024Hyderabad, India
  • Participated in Major Incident Management calls, providing real-time security analysis, incident updates and technical guidance during critical security events
  • Led advanced security alert investigations using Kibana SIEM and escalated high-severity incidents
  • Mapped adversary TTPs to MITRE ATT&CK; to support proactive threat hunting
  • Conducted deep-dive phishing and email threat investigations, analyzing headers, URLs, attachments and payloads
  • Performed malware and IOC analysis and used findings to enhance detection rules
  • Conducted vulnerability assessments using Nessus, prioritized findings by risk and provided remediation guidance to IT teams
  • Maintained incident documentation in ServiceNow, supporting SLA compliance and audit-ready evidence
  • Improved SOC processes through detection tuning, incident-response playbooks and ISO/IEC 27001 monitoring/documentation support
Security Associate
DIAGONAL SOFTWARE PVT LTD
Sep 2019 — Sep 2020Hyderabad, India
  • Provided 24×7 SOC monitoring across firewall, antivirus, domain controller and network-device telemetry
  • Monitored and investigated security offenses using IBM QRadar SIEM, performing initial triage and severity-based escalation
  • Performed log analysis and alert validation to identify potential threats and reduce false positives
  • Investigated phishing and spam incidents and provided remediation guidance to affected users
  • Prepared SOPs and Work Instructions to improve investigation efficiency and consistency
  • Supported Active Directory operations including account creation, access provisioning and account enable/disable requests
  • Escalated confirmed incidents to L2/L3 analysts with complete analysis and supporting artifacts
Skills
SIEM: IBM QRadar, Kibana, Microsoft SentinelEDR/XDR: SentinelOne, CrowdStrike, Microsoft Defender for EndpointSOAR / IR: The Hive, ResilientEmail Security: Proofpoint TAP/TRAP, Microsoft Defender for Office 365Network Security: Cisco Umbrella, Check Point, Firepower, Cloudflare WAFCloud Security: AWS GuardDuty, Azure Defender, Microsoft CloudVulnerability / ITSM: Nessus, ServiceNowOperating Systems / Query: Windows, Linux, S1QL, KQL
Education
Bachelor of Technology, Electrical and Electronics Engineering
GVIT Bhimavaram
2010 — 2014
Certifications
CompTIA Security+ Certified
Languages
English
Professional working proficiency