Subha Saha
Security Delivery Analyst - SOC | CEH | Incident Response | SIEM | EDR | XDR | XSOAR
- Role
- Security Delivery Analyst at Accenture in India
- Location
- Bengaluru, KA, IN
- LinkedIn followers
- 500 followers
About Subha Saha
As a Cybersecurity Analyst with over 4 years of experience, I specialize in real-time incident response, advanced threat detection, and log analysis using SIEM/ SOAR/ XDR Platforms. I’ve worked extensively across both on-premise and Azure cloud environments, focusing on investigation, threat hunting, and optimizing response workflows for faster containment and compliance readiness.I hold several relevant certifications, including:Certified Ethical Hacker (CEH), Microsoft Azure Fundamentals (AZ-900), Splunk 7.x Fundamentals, Cortex XSOAR 6.9 Analyst, and an Executive PG Program in Cybersecurity from IIT Roorkee & iHub DivyaSampark, further validating my hands-on expertise in modern SOC operations.Key Highlights:Specialized in Splunk ES for log analysis, threat detection, correlation rule tuning, analyzing 10-15 escalated alerts on daily basis, recognized by L3 and leadership multiple time for the investigative approachAchieved ~30% reduction in false positive alerts by refining correlation rules, eliminating noise, and integrating meaningful IOCs.Performed RCA on advanced threats mapped to MITRE ATT & CK using correlated logs (CrowdStrike, Defender, MCAS), and conducted threat hunts based on Threat Intelligence inputs.Suggested enhancements to XSOAR playbooks, including additional automation steps, to streamline investigations and accelerate L1/L2 incident resolution.Regularly presented SOC metrics and incident trends to leadership, enabling data-driven decision-making and continuous improvement in detection and response.Experience:Security Delivery Analyst – Accenture: Specialized in SIEM (Splunk ES), XDR/EDR analysis, Azure/MCAS log review. Suggested playbook improvements and led intel-based threat hunts. As an L2 analyst worked as an shift lead handling complex issue and guiding junior members.Senior SOC Analyst – Capgemini: Handled alert triage, RCA, SOPs, and threat hunting. Performed log analysis and vulnerability scans using Splunk and Qualys.Core Skills:SIEM (Splunk ES)| Alert Triage & RCA | Log Correlation & Use Case Design | EDR (CrowdStrike, Defender)| XSOAR Playbooks | Azure Security & MCAS | MITRE ATT & CK | Threat Hunting Eager to contribute in Advanced SOC L2 / Cloud SOC / Threat Hunting roles where I can drive effective detection engineering, response automation, and threat visibility through expert-level use of Splunk and modern SOC toolsets.Let’s connect if you\'re looking to level up your detection and response capabilities.
Experience
Security Delivery Analyst
Jan 2024 — Present · Bengaluru, IN
Deep analysis of incident Security incidents escalated by L1 analyst. Acknowledged 15+ incidents on an average on daily basis.•Identify and ingest indicators of compromise (IOCs), e.g. malicious IPs/URLs, into network tools/applications•Stay up to date with current vulnerabilities, attacks, and countermeasures with security blogs•Monitored and tracked incident over XSOAR platform to achieve improvement on SOC Metrics•Analyzed security event data from the network with SIEM, EDR (Splunk ES, Crowd Strike, Defender) tools, azure user audit logs, MCAS logs to perform Root Cause Analysis of security incidents•Keep track of false positive cases and shared the related report to higher management. Worked on refining correlation rules post approvals•Actively hunt for adversaries shared by Threat Intelligence team across the environment•Analyzed log over cloud environments (Azure, MCAS) to identify potential security incidents•Monitored alerts for email threat and take required action on Proofpoint email gateway to prevent phishing incidents•Participated in development and documentation of Incident Response Plan.•Structured use case specific investigation flow chart to automate primary incident response in XSOAR platform•Collaborated with cross functional teams and external stakeholders to identify and mitigate security risks across the environment.
Education
Techno India College Of Technology
Bachelor of Technology - BTech
2016 — 2020
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.