Harish kumar
Security Analyst
Bengaluru, India
#OpenToWork
About
Cybersecurity professional with over 4 years of hands-on experience in Security Operations Centers (SOC), focusing on threat detection and incident response. Skilled in using tools like IBM QRadar and the ELK Stack to monitor security events and respond quickly to potential risks. Knowledgeable in ISO 27001 standards, with a strong focus on improving threat detection and maintaining a secure environment. Certified Ethical Hacker (CEH) with practical experience in protecting networks and endpoints from cyber threats.
What I'm looking for
Information Security Analyst, GRC Analyst.
Experience
Security Analyst
Cyber Radar Systems
Dec 2023 – Jan 2026
* Enforced Information Security Policies and supported Governance, Risk, and Compliance (GRC) initiatives aligned with ISO/IEC 27001 and NIST frameworks.
* Conducted Information Security Risk Assessments by identifying risks, evaluating business impact, recommending mitigation measures, and tracking remediation activities.
* Acted as SOC Compliance Liaison during ISO 27001 internal audits by mapping SOC processes to ISO controls, identifying gaps, and developing Risk Treatment Plans (RTPs).
* Evaluated IT General Controls (ITGC) and security controls, identified deficiencies, and recommended Corrective and Preventive Actions (CAPA) to reduce risk exposure.
* Prepared audit reports, compliance evidence, governance reports, and remediation tracking documentation detailing severity, impact, and remediation status.
* Collaborated with IT, Security, Compliance, and Management teams to support governance initiatives, audit readiness, and remediation management.
* Worked with senior management to remediate audit findings and implement compliant security controls aligned with organizational and regulatory requirements.
* Delivered Cybersecurity Awareness Training sessions to employees, promoting security best practices and strengthening security culture.
* Utilized Threat Intelligence Platforms and the MITRE ATT&CK Framework to enhance threat analysis, detection use cases, and threat visibility.
* Monitored and investigated security events using SIEM platforms including IBM QRadar and ELK Stack.
* Performed log analysis, alert triage, and network traffic analysis to identify anomalies and support incident response activities.
* Analyzed, prioritized, and escalated security alerts while coordinating with Incident Response (IR) teams during containment and remediation phases.
* Supported vulnerability assessment and security monitoring activities to strengthen defensive security operations.
ISO 27001ISMSAuditRisk Management
SOC Analyst
Marlabs Innovation Pvt Ltd
Aug 2021 – Nov 2023
•Handled an average of 30 security alerts per day, ensuring prompt response and mitigation to minimize potential threats.
•Conducted analysis of 500+ logs and security equipment rules, leading to the identification of critical vulnerabilities and enhancing security configurations.
•Mitigated and validated the security of 100+ systems, reducing the risk of infection and ensuring safe reintegration into the network.
•Monitored security events using SIEM (ELK Stack), analyzed significant events, and processed reports for malicious activity, resulting in a 30% decrease in cybersecurity incidents.
•Monitored and protected against external and internal threats leveraging Office 365 cloud app security.
•Provided detailed remediation suggestions to device owners based on threat detection, analyzed behavioral indicators, and used Cisco Secure X Endpoint Detection Response for device isolation.
•Analyzed and identified 150+ phishing emails, domains, and IPs using Sandbox and open-source tools, achieving a 60% reduction in successful phishing attempts.
•Maintained a 100% compliance rate in documenting investigation details and actions taken in the ticketing system, ensuring clear audit trails for all security incidents.
•Monitored Zscaler Digital Experience (ZDX) dashboard to ensure global user systems' functionality and security.
•Conducted comprehensive daily reviews of 100+ logs and alerts from various security devices, ensuring timely detection and response to potential threats.
•Provided mitigations for major security threats, vulnerabilities, and exploits to the Cybersecurity and Infrastructure team using CISA alerts.
•Responded to identified threats and contained them using custom detection rules, policy management, and machine isolation.
SIEM MonitoringPhishing AnalysisEndpoint Security
SOC Analyst Trainee
Secucybers Technology Private Limited
Feb 2021 – Jul 2021
•Simulated and detected security incidents using IBM QRadar, setting up correlation rules and dashboards for real-time threat monitoring.
•Conducted log aggregation and false positive analysis, ensuring accurate incident detection and reporting as per SOC processes (PICERL).
•Utilized threat intelligence tools (VirusTotal, IPvoid) to identify IOCs and provide actionable insights on potential threats.
IBM QRadarThreat IntelligenceLog Analysis
Education
T John Institute of Technology
Mechanical Engineer
2020
Certifications
ISO 27001:2022 Certified Lead Implementer
ISO
2022 – No expiry
ISO 27001:2022 Certified Lead Auditor
ISO
2022 – No expiry
Certified Ethical Hacker
EC-COUNCIL
Skills
NISTISO 27001Office 365Zscaler ZDXCisco Secure XWiresharkNMAPIBM QRadarELK Stack
Languages
English (Full professional proficiency)Hindi (Native or bilingual proficiency)Marathi (Native or bilingual proficiency)Kannada (Native or bilingual proficiency)