SOC Analyst | SIEM Engineer | Threat Detection Enthusiast
Entry-Level SOC Analyst with hands-on experience in SIEM monitoring, alert triage, incident investigation, threat detection, and security operations using Microsoft Sentinel, Splunk, QRadar, Snort IDS/IPS, Azure Security Services, and Threat Intelligence Platforms.
Hello! I am Rahul, a cybersecurity professional focused on Security Operations Center practices, SIEM engineering, threat detection, incident investigation, and cloud security monitoring.
My hands-on experience includes Microsoft Sentinel, Splunk, Snort IDS/IPS, Azure monitoring, Entra ID security, threat intelligence integration, and SOC operations workflows. I enjoy transforming security telemetry into actionable detections and helping organizations improve visibility into potential threats.
Learner Story — Official Publication
My cybersecurity learning journey, career transition, and commitment to continuous professional development were selected and published by Coursera as an official Learner Story.
Read My StoryActive threat detection and mitigation through SIEM monitoring
Awareness training and security education sessions conducted
I4C National Cybercrime Investigation Program training
Consistent on-time incident resolution and reporting
Training Sessions Delivered
Law Enforcement Personnel Trained
Government Programs Delivered
Delivered cybersecurity awareness and hands-on security training sessions for Indian Army Officers covering cyber threats, network security, security operations, and digital defense practices.
Delivered cybersecurity, SOC operations, threat detection, OSINT, network forensics, and cybercrime investigation training programs for state police personnel under government-sponsored initiatives.
Built a complete Microsoft Sentinel environment including Resource Groups, Log Analytics Workspace, Sentinel Workspace, RBAC controls, Content Hub integrations, DCR configuration, Threat Intelligence feeds, and custom KQL detection rules.
Architected a Splunk-based SIEM platform supporting log ingestion, event correlation, SOC dashboards, ticketing integration, and automated alert escalation workflows.
Implemented a production-grade Snort NIDS with custom detection rules, network monitoring workflows, suppression tuning, and automated alert generation for real-time threat detection.
Developing detection rules, validating alerts, identifying suspicious activity, and improving detection coverage across the enterprise.
Building Microsoft Sentinel and Splunk environments, integrating data sources, creating analytics rules, and managing log pipelines.
Alert triage, investigation, classification, containment support, and escalation procedures following structured SOC playbooks.
Azure monitoring, Entra ID security, RBAC administration, IAM controls, and identity protection across cloud environments.
IOC ingestion, enrichment, threat feeds, intelligence correlation, and security analytics for proactive defense.
Python, PowerShell, KQL, workflow automation, and security operations optimization for faster detection and response.
Not just theoretical — I have built, configured, and operated Microsoft Sentinel and Splunk environments in real security operations contexts.
Gained practical SOC experience through a formal internship at NIELIT, contributing to active threat monitoring and incident prevention.
Proficient in both leading SIEM platforms, including workspace setup, analytics rules, KQL queries, and integration architecture.
Approach security analytically — focused on detecting behavioral anomalies, building detection logic, and improving security visibility.
Delivered 100+ cybersecurity sessions and trained 130+ law enforcement officers — strong communicator capable of bridging technical and non-technical audiences.
Actively pursuing certifications, building lab environments, and staying current with threat intelligence to continuously grow my detection engineering capabilities.
Have an opportunity, want to collaborate, or just want to talk cybersecurity? I'd love to hear from you.