Shiva Deepthi
Open to opportunitiesSplunk | Microsoft Sentinel | CrowdStrike EDR | Active Directory | Nessus | Azure Security | SIEM
Toronto, ON
About
• Results-driven Cybersecurity Analyst with 5 years of experience in SOC environments, specializing in threat detection, incident response, vulnerability management, endpoint security, and cloud security monitoring. • Hands-on experience using SIEM platforms such as Splunk and Microsoft Sentinel to monitor, investigate, and correlate security events, improving alert visibility and detection accuracy by up to 35%. • Skilled in real-time security monitoring, alert triage, log analysis, and incident escalation, helping reduce false positives by 25% through improved correlation rules and alert tuning. • Experienced in CrowdStrike Falcon EDR for endpoint investigation, malware containment, host isolation, threat hunting, IOC analysis, and remediation of suspicious endpoint activities. • Proficient in conducting endpoint security investigations involving malware alerts, unauthorized access attempts, suspicious PowerShell activity, abnormal process execution, and lateral movement indicators. • Strong experience in Vulnerability Management using Nessus and Qualys, including vulnerability scanning, CVE analysis, risk prioritization, patch tracking, and remediation validation. • Demonstrated success in conducting vulnerability assessments across 300+ assets and supporting remediation of 90%+ critical vulnerabilities within SLA timelines. • Skilled in Incident Response using NIST and SANS frameworks, including detection, analysis, containment, eradication, recovery, documentation, and post-incident review. • Experienced in Microsoft Sentinel and Azure Security Center for cloud security monitoring, KQL-based investigation, security event analysis, and hybrid environment threat detection. • Strong background in IAM including Active Directory security, Azure Active Directory, MFA, PAM, access reviews, and identity-based risk reduction. • Hands-on knowledge of Network Security, including firewall monitoring, IDS/IPS, proxy logs, Wireshark, Nmap, Burp Suite, Metasploit, and network traffic analysis. • Proficient in GRC & Compliance activities aligned with ISO 27001, NIST, PCI-DSS, and GDPR, including audit support, gap analysis, risk assessment, and remediation planning. • Improved incident response efficiency by 30% through workflow optimization, automation support, SOAR integration, and standardized triage procedures. • Strong analytical, problem-solving, and decision-making skills with the ability to investigate complex security incidents, prioritize critical alerts, and communicate risks clearly. • Collaborative and detail-oriented cybersecurity professional with strong documentation, teamwork, adaptability, ownership, and continuous learning skills, committed to strengthening organizational security posture
Skills
- Active Directory
- Burp Suite
- DNS
- Linux
- Metasploit
- Nessus
- Nmap
- Okta
- Python
- Splunk
- TCP/IP
- Wireshark
Experience
Cybersecurity Analyst
Technip FMC
Dec 2022 to Present
Canada
• Monitored and analysed security alerts in Splunk, QRadar, Microsoft Sentinel, triaging and escalating incidents. • Secured infrastructure with Palo Alto firewalls, IDS/IPS, VPNs, reducing unauthorized access attempts by 40%. • Conducted vulnerability scans with Nessus & Qualys, integrating findings into ServiceNow for remediation tracking. • Applied OWASP best practices in web app security, ensuring compliance with ISO 27001 & NIST. • Enhanced cloud IAM policies across AWS & Azure, preventing unauthorized access to workloads. • Integrated PLM security controls with Teamcenter Viewer, ensuring secure access in engineering workflows. • Supported ECN (Engineering Change Notices) and Class 1–4 change management processes, aligning cybersecurity with engineering governance. • Delivered phishing awareness training, raising detection rates by 25%. • Evaluated and enhanced access governance processes, reducing manual intervention through automation while maintaining risk controls. • Delivered risk assessments of IAM controls, identifying security gaps and ensuring alignment with enterprise security policies. • Produced identity governance analytics and access review reports using Power BI to support security and compliance initiatives. • Created security dashboards and executive reports to provide visibility into IAM risks, compliance metrics, and remediation efforts. • Collaborated with application and infrastructure teams to implement cloud security controls in AWS and Azure environments aligned with NIST, ISO 27001, and SOC frameworks. • Identified vulnerabilities and security risks based on regulatory requirements including GDPR, PCI DSS, HIPAA, and organizational security policies. • Maintained IAM process documentation, SOPs, and governance workflows to support audits and operational continuity. • Championed continuous improvement initiatives to automate identity lifecycle management processes and improve user experience.
Security / Risk Operations Analyst
Stags Innovation
Jul 2020 to Jul 2022
India
• Monitored SOC alerts in SIEM platforms (Splunk, QRadar), triaging and escalating incidents. • Investigated suspicious activity across endpoints and networks, supporting containment and remediation. • Conducted vulnerability scans with Nessus/OpenVAS, reporting findings and tracking remediation progress. • Assisted in phishing analysis by reviewing reported emails, isolating malicious payloads, and supporting user awareness. • Documented incidents, created playbooks, and improved escalation workflows to reduce response times. • Collaborated with IT teams to enforce IAM policies and strengthen endpoint security. • Mentored junior analysts on SOC procedures, improving detection accuracy and SLA adherence.
Cyber Security Analyst
Infosys
Jun 2020 to Feb 2022
India
• Performed initial alert triage, investigation, and escalation for suspicious activities, malware alerts, phishing attempts, and unauthorized access attempts. • Monitored security alerts and events in a SOC environment using SIEM tools such as Splunk and Microsoft Sentinel. Analyzed security logs from firewalls, endpoints, servers, Active Directory, and network devices to identify potential threats and anomalies. • Supported incident response activities including detection, analysis, containment, escalation, documentation, and closure of security incidents. • Investigated endpoint security alerts using EDR tools and coordinated with support teams for malware containment and remediation. • Created and updated incident tickets in ServiceNow, ensuring accurate documentation of findings, actions taken, and resolution status. Conducted basic threat hunting using indicators of compromise, suspicious IPs, domains, hashes, and user behavior patterns. • Monitored failed login attempts, privilege escalation activities, abnormal user behavior, and suspicious Active Directory events. • Assisted in vulnerability management activities by reviewing scan results, validating risks, and coordinating patch remediation with technical teams. • Prepared daily and weekly SOC reports covering alert trends, incident status, false positives, escalations, and remediation progress. • Followed standard SOC playbooks, escalation procedures, and incident response frameworks such as NIST and SANS. • Collaborated with IT and security teams to improve detection rules, reduce false positives, and strengthen overall security monitoring.
SOC Analyst
Infosys
Jan 2017 to Jun 2020
India
• Conducted vulnerability assessments across servers, endpoints, applications, databases, and network infrastructure to identify security risks, misconfigurations, and control gaps. • Performed vulnerability scanning using Nessus and Qualys, analyzed scan results, removed false positives, and prioritized findings based on CVSS score, exploitability, asset criticality, and business impact. • Managed end-to-end vulnerability lifecycle activities, including detection, validation, risk classification, remediation tracking, retesting, and closure. • Identified and tracked critical and high-risk CVEs, coordinating with infrastructure, application, and security teams to ensure timely remediation within SLA timelines. • Supported remediation of vulnerabilities related to missing patches, outdated software, insecure protocols, weak configurations, open ports, and unsupported systems. • Prepared detailed vulnerability reports including risk ratings, affected assets, technical evidence, business impact, remediation recommendations, and closure status. • Maintained vulnerability trackers and dashboards to monitor remediation progress, recurring issues, SLA breaches, risk exceptions, and pending action items. • Collaborated with system owners and technical teams to validate patch deployment, perform retesting, and confirm successful vulnerability closure. • Assisted in risk assessment and prioritization of vulnerabilities by mapping exposure levels, threat intelligence, and potential business impact. • Reviewed vulnerability trends and recurring findings to recommend process improvements and strengthen overall security posture. • Supported internal and external audit activities by providing vulnerability reports, remediation evidence, risk acceptance details, and compliance documentation. • Worked closely with SOC, infrastructure, and application teams to correlate vulnerability data with security events and prioritize high-risk assets exposed to active threats. • Followed industry best practices and security frameworks such as NIST, ISO 27001, and PCI-DSS to support risk management, compliance, and vulnerability governance activities. • Delivered accurate documentation and status updates to stakeholders, demonstrating strong analytical thinking, attention to detail, communication, ownership, and cross-functional collaboration.
IT Support Analyst ( Network)
Infosys
Jun 2016 to Dec 2016
India
• Provided L1/L2 technical support for hardware, software, network, access, and application-related issues within SLA timelines. • Managed incidents and service requests using ticketing tools, ensuring proper documentation, prioritization, escalation, and closure. • Supported Windows systems and Active Directory, including password resets, account unlocks, user access, and group membership updates. • Troubleshot VPN, LAN/Wi-Fi, printer, shared drive, DNS/DHCP, and basic connectivity issues. • Assisted with patching, antivirus updates, endpoint health checks, and system compliance activities. • Coordinated with infrastructure, application, and security teams to resolve issues and reduce business downtime. • Created knowledge base documentation and troubleshooting steps to improve first-call resolution. • Demonstrated strong communication, problem-solving, customer service, ownership, and time management skills in a fast-paced IT support environment.
Education
SAULT College
M.S., Cyber Security
Canada
2023 to 2025
University of Windsor
Masters of Management, Logistics and Supply Chain Management
Canada
2023 to 2024
Matrusri Engineering College
B.E., Computer Science
India
2018 to 2022
SRM University
Bachelors, Electronics and Instrumentation Engineering
India
2012 to 2016
Licences & certifications
CompTIA Security+
AWS Certified Security – Specialty
Microsoft Certified: Security Operations Analyst Associate
Google Cybersecurity
CompTIA Security +
