Skip to content
AS

Ashish Sivaiah

Security Analyst

๐Ÿ“ Chicago, IL, USA

๐Ÿ”ดHODLing

Security analyst with 4+ years of hands-on SOC experience detecting, investigating, and neutralizing threats across enterprise and cloud environments. Skilled in the full incident response lifecycle using SIEM platforms (Splunk, Microsoft Sentinel, QRadar), EDR/XDR tools (CrowdStrike Falcon, Defender XDR), and SOAR automation that reduced MTTR by 50%. Experienced in threat hunting, vulnerability management, and cloud security (AWS, Azure, GCP).

Skills

Incident Response & SOC Operations9/10
EDR/XDR (CrowdStrike Falcon, Defender XDR, SentinelOne)9/10
SIEM (Splunk, Microsoft Sentinel, QRadar)9/10
Threat Hunting & MITRE ATT&CK8/10
Compliance (NIST, ISO 27001, PCI DSS, HIPAA, GDPR)8/10
Firewall Administration (Palo Alto, Fortinet, Cisco ASA) (8/10)IAM & Active Directory / Azure AD (8/10)Cloud Security (AWS, Azure, GCP) (8/10)Python (8/10)PowerShell (8/10)SOAR (Cortex XSOAR, Phantom, TheHive) (8/10)Vulnerability Management (Nessus, Qualys) (8/10)Zero Trust Architecture (7/10)Digital Forensics (Wireshark, Volatility, Autopsy) (7/10)Elastic SIEM (7/10)IDS/IPS (Suricata, Snort) (7/10)Malware Analysis (7/10)Threat Intelligence (MISP, Recorded Future, ThreatConnect) (7/10)Bash (7/10)Terraform (6/10)

Work Experience

Security Analyst

CrowdStrike

Oct 2024 โ€” Present

Triaged and investigated P0/P1 security incidents in a 24/7 SOC environment, analyzing 400+ alerts/month using Splunk and CrowdStrike Falcon. Automated SOC tasks in Cortex XSOAR using Python/PowerShell/Bash, reducing MTTR by ~50%. Performed endpoint investigations in Falcon and Defender XDR. Conducted threat hunting across IAM, SSO, and EDR telemetry. Developed and tuned 30+ custom SIEM correlation rules mapped to MITRE ATT&CK. Performed digital forensics, vulnerability management, and multi-cloud hardening (AWS, Azure, GCP). Supported FedRAMP, PCI DSS, HIPAA, and GDPR compliance assessments.

Security Analyst

HCLTech

Jun 2020 โ€” Jul 2023

Operated in a 24/7 Global SOC monitoring SIEM dashboards and analyzing alerts from endpoint, firewall, and email platforms. Investigated suspicious activities using SentinelOne EDR. Administered firewall policies across Palo Alto, Fortinet, and Cisco ASA (500+ configuration changes, 30% reduction in misconfigurations). Applied Zero Trust principles reducing unauthorized access by 40%. Conducted Active Directory and Azure AD audits. Administered Proofpoint Email Security reducing inbound phishing by 35% across 10,000+ mailboxes. Performed vulnerability assessments remediating 200+ high-risk CVEs. Supported PCI DSS, HIPAA, and GDPR compliance readiness.

Education

Illinois Institute of Technology

MSc ยท Cybersecurity

2023 โ€“ 2025

Presidency University

BSc ยท Electronics and Communication Engineering

2017 โ€“ 2021