Swagat Parija
Cyber Defense Analyst L2 Global Security Operations @McDonald's
Signup · Get unlimited contacts
WORK HISTORY
Cyber Defense Analyst L2 Global Security Operations @McDonald's
Hyderabad, IN
DFIR Analyst L2 || SIEM Detection, Threat Hunting & Forensics Led end-to-end DFIR investigations, including alert validation, incident scoping, root cause analysis, and attacker timeline reconstruction across enterprise environments. Performed digital forensics using EDR telemetry, Windows artifacts, memory analysis, and log correlation to identify patient zero and attack progression. Conducted targeted threat hunting based on incident patterns, detection gaps, and emerging adversary behaviors to uncover stealthy activity. Developed and refined SIEM detection rules, supporting use-case tuning, false-positive reduction, and improved alert fidelity. Validated containment and remediation actions, ensuring incidents were fully resolved before closure and reducing risk of reinfection. Collaborated closely with SOC, detection engineering, and platform teams to feed DFIR learnings back into SIEM and EDR detections. Automated investigation and enrichment workflows using scripting to improve response efficiency and reduce analyst effort. Participated in shift operations, case reviews, and quality audits, maintaining investigation standards and response consistency across teams.
EDUCATION
Udacity
Nanodegree, AI Programming with Python Nanodegree
L.R DAV Public School, Cuttack
High School
Siksha 'O' Anusandhan University
Bachelor of Technology - BTech, Computer Science
ABOUT SWAGAT PARIJA
With around 5 years of experience across DFIR, SIEM engineering, and SOC operations, I specialize in incident response, threat hunting, and detection engineering within enterprise security environments. I have hands-on experience handling end-to-end investigations, including root cause analysis, attacker timeline reconstruction, and containment validation, while also contributing to SIEM rule development and tuning to improve detection quality.Proficient with SIEM and EDR platforms such as Splunk, QRadar, SentinelOne, and CrowdStrike, I have worked on developing and optimizing detections mapped to the MITRE ATT & CK framework, supporting reduced false positives and improved response effectiveness. My work bridges DFIR and detection by feeding real incident learnings back into SIEM and EDR use cases to strengthen overall security posture.Certified in GCIH, AZ-500, CCFR, and Splunk Enterprise Admin, I bring a practical, incident-focused approach to cybersecurity, with an emphasis on accuracy, operational efficiency, and continuous improvement. I am particularly interested in strengthening detection coverage, improving response workflows, and enabling effective collaboration between DFIR and SOC teams. Let’s connect to discuss DFIR, SIEM detection strategies, and incident response best practices.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.