Hi, I'm Neel.
Security Analyst with 2 years of hands-on SOC experience — building detection logic, leading investigations, and engineering SIEM dashboards that cut alert fatigue and sharpen visibility.
I work in enterprise SOC operations, focused on threat detection, incident response, and SIEM engineering. Day to day that means building dashboards and correlation logic in Sumo Logic, threat hunting across Defender and XDR queries, and serving as the escalation point when an alert needs a deeper look. I've led investigations that internal teams — and outside responders — couldn't fully resolve, and I care about strengthening SOC maturity through automation, clear SOPs, and mentoring newer analysts.
Learn MoreSecurity Analyst with two years of hands-on experience in enterprise SOC operations, threat detection, incident response, and SIEM engineering. Proven track record of building high-impact dashboards, developing detection logic, leading complex investigations, and serving as the escalation point for critical alerts — with a focus on strengthening SOC maturity through automation, SOP development, and mentoring junior analysts.
- Serve as the primary escalation point for critical alerts, providing rapid triage, deep-dive investigations, and clear reporting to leadership.
- Built multiple high-value dashboards in Sumo Logic (admin accounts, unapproved applications, sensitive activity), improving visibility and reducing analyst workload.
- Conduct threat hunting using Sumo Logic, Defender, and XDR queries; review OSINT threat reports and translate findings into actionable detection logic.
- Led a critical user compromise investigation and identified the root cause after both internal teams and Unit42 were unable to determine it.
- Review SOPs created by junior analysts and ensure alignment with SOC workflows and incident response best practices.
- Built Power Automate workflows to update SIEM term lists, reducing manual effort and improving detection accuracy.
- Enhanced phishing and malware automated playbooks to improve reliability and support SOC automation initiatives.
- Engineered a Sumo Logic dashboard that reduced approximately 40 alerts per day, significantly lowering alert fatigue and improving SOC efficiency.
- Tuned correlation rules and signals to reduce false positives and increase detection fidelity across multiple data sources.
- Performed 24/7 monitoring of hybrid environments, responding to malware, exploitation attempts, and suspicious activity.
- Built custom use cases and correlation searches to strengthen detection capabilities.
- Conducted forensic investigations, extracted log data, and coordinated mitigation with cross-functional teams.
- Created and refined SOPs for analysis, containment, eradication, and recovery, improving consistency and response speed.
- Managed IDS/IPS, firewalls (Cisco, Linux, Windows), WAFs, and XDR tools to safeguard network and application environments.
- Ran SQL queries and managed BizTalk Server operations daily to support EDI workflows.
- Generated Power BI reports with clear visualizations for leadership and accounting teams.
- Troubleshot EDI processes and data flows, ensuring accurate transmission of business documents via EDI/XML.
- Managed relationships with eProcurement partners (Ariba, Coupa, etc.) and coordinated testing with AX development teams.
Let's talk SOC operations, detection engineering, or incident response.