S. V. Gautham
Associate Engineer at Brillio | SOC Analyst handling alerts| Microsoft Sentinel & KQL | Cloud & Identity Security | Incident Response | Cloud Security | Building toward Red Team🛡️
- Role
- Associate Engineer at Brillio
- Location
- Bengaluru, KA, IN
- LinkedIn followers
- 500 followers
About S. V. Gautham
I work as a SOC Analyst investigating high-volume security activity across enterprise cloud environments. On a typical shift, I triage and analyze 800–1500+ alerts spanning Azure AD, Microsoft Defender, VPN, and endpoint telemetry, identifying suspicious authentication behavior, lateral movement patterns, and policy violations.Beyond monitoring, I contribute to improving detection quality. I’ve written and optimized KQL detection queries in Microsoft Sentinel, tuned analytics rules to reduce false positives, and escalated high-severity incidents with structured analysis aligned to the MITRE ATT & CK framework.Working directly with real attack patterns changed how I see cybersecurity. I don’t just want to respond to threats I want to understand attacker behavior, simulate it, and ultimately anticipate it.To move in that direction, I’m intentionally expanding into cloud security and offensive security. I’m strengthening my knowledge in Azure identity protection, SIEM engineering, and network security fundamentals, while actively training on hands-on platforms like TryHackMe and structured SOC learning paths.I also bring a foundation in AI and machine learning, and I’m particularly interested in how behavioral analytics and intelligent detection can improve threat identification and reduce analyst fatigue.Today, I help security teams improve detection accuracy and incident response efficiency. My long-term goal is to bridge blue-team operations, cloud security architecture, and red-team simulation to build more resilient systems.If you\'re building a security team in a cloud-first environment, I’m open to connecting and discussing opportunities where I can contribute and continue growing.
Experience
Associate Engineer
Jan 2026 — Present · Bengaluru, IN
Monitored and triaged 200–300+ security alerts per shift in Microsoft Sentinel across Azure AD, Defender, VPN, firewall, and endpoint logs, ensuring timely detection and response within SLA.• Performed device health monitoring for 100+ assets (servers, firewalls, endpoints) by identifying reporting and non-reporting logs using KQL queries, improving visibility into log ingestion gaps.• Analyzed daily log ingestion and billing data, tracking data consumption patterns and identifying non-billable sources, contributing to optimized log management and cost awareness.• Conducted 50+ alert investigations per shift using KQL queries, identifying anomalies such as impossible travel, brute-force attempts, and malicious IP activity.• Reduced false positives by ~20–30% through effective alert validation and correlation across identity, endpoint, and network logs.• Utilized Microsoft Defender, CrowdStrike, and Zscaler to perform deeper endpoint and network analysis, improving investigation depth beyond SIEM alerts.• Monitored and investigated 200–500 DLP alerts per shift using Microsoft Purview, identifying unauthorized uploads, downloads, and potential data exfiltration attempts.• Documented 100% of incidents and investigations in ServiceNow, ensuring audit readiness and structured incident tracking.• Delivered daily shift handovers and participated in SOC briefings, ensuring seamless transition and continuity of incident response.• Generated weekly reports on incident trends, alert volumes, and response metrics, supporting data-driven security improvements.•Conducted incident investigations aligned to MITRE ATT & CK tactics, including Initial Access, Persistence, Privilege Escalation, and Lateral Movement. •Escalated high-severity (P1/ P2) incidents to Tier-2 teams with detailed root cause analysis and recommended containment actions.• Performed end-of-shift health checks on systems and servers, ensuring 99%+ operational availability of security infrastructure.
Education
Shiv Nadar University
Bachelor of Technology , Electrical and Computer Engineering
SAI International School
High School Diploma
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.