Guneet Sidhu
Security Operations Center Analyst @Cineplex
Signup · Get unlimited contacts
WORK HISTORY
Security Operations Center Analyst @Cineplex
Toronto, ON, CA
Monitor and analyze security alerts using SIEM platforms including Splunk, Microsoft Sentinel, and QRadar to detect potential threats in real time.Investigate and respond to security incidents including phishing attacks, malware infections, insider threats, and suspicious network activity across L1–L3 escalations.Perform log analysis, packet analysis, and forensic investigations to validate alerts and reduce false positives.Utilize EDR solutions such as CrowdStrike Falcon and Windows Defender ATP to identify and isolate compromised endpoints.Develop and maintain incident response playbooks and SOC operational procedures to improve incident response efficiency.Collaborate with IT and infrastructure teams to perform root cause analysis and implement remediation strategies.Conduct proactive threat hunting to identify indicators of compromise and reduce attacker dwell time.Generate SOC metrics reports and dashboards to track incident trends and improve security operations.Tools: Splunk, Microsoft Sentinel, QRadar, CrowdStrike Falcon, Wireshark, Nmap, Nessus, Qualys, ServiceNow, JIRA.
EDUCATION
St. Joseph's School
Class 10, Class 10
CHANDIGARH UNIVERSITY
Bachelor's degree, Computer Science
Vancouver Community College (VCC)
Postgraduate Degree, Network technology administration and security
St.Fateh School
Class 12, Non Medical
ABOUT GUNEET SIDHU
Cybersecurity Operations Specialist with 3+ years of experience in Security Operations Centers (SOC), specializing in threat detection, incident response, and security monitoring across banking and enterprise environments.Experienced in analyzing and responding to security alerts using SIEM platforms including Splunk, Microsoft Sentinel, and IBM QRadar. Skilled in investigating phishing attacks, malware incidents, insider threats, and suspicious network activity while ensuring rapid containment and remediation.Proficient in working with EDR solutions such as CrowdStrike Falcon, Windows Defender ATP, and SentinelOne to detect and respond to endpoint threats. Strong hands-on experience with threat intelligence tools including VirusTotal, AlienVault OTX, Maltego, and OSINT frameworks to identify indicators of compromise (IOCs) and support proactive threat hunting.Experienced in log analysis, packet inspection, vulnerability management, and incident response lifecycle aligned with frameworks such as NIST, MITRE ATT & CK, ISO 27001, and ITIL.Technical strengths include SIEM monitoring, EDR investigations, phishing analysis, vulnerability scanning, incident response playbook development, and automation using Python, Bash, and PowerShell.Currently focused on strengthening enterprise security posture by improving detection rules, reducing false positives, and implementing proactive threat-hunting techniques.Key Skills:• Security Monitoring & Incident Response• SIEM (Splunk, Microsoft Sentinel, QRadar)• Endpoint Detection & Response (CrowdStrike, Defender ATP)• Threat Intelligence & OSINT• Vulnerability Management (Nessus, Qualys)• Cloud Security (Azure Security, O365 Security)• Network Security & Log Analysis• Scripting & Automation (Python, PowerShell, Bash)Open to opportunities in SOC Operations, Threat Detection, and Cybersecurity Engineering.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.