Work Preference
Summary
Overview
Work History
Education
Skills
Certification
Accomplishments
Languages
Awards
Timeline
Generic
Open To Work

ANKIT KUMAR

New Delhi,India

Work Preference

Job Search Status

Open to work

Location Preference

RemoteOn-SiteHybrid

Summary

Cybersecurity professional with over 7 years of experience in SOC management and cloud security operations. Expertise in incident response, vulnerability assessments, and leading cross-functional teams to enhance security postures. Currently overseeing IT security for a national platform, ensuring compliance and operational integrity.

Overview

1
1
Certification
8
8
years of professional experience

Work History

Manager - IT Security and Cyber Security

Karmayogi Bharat (IGOT)
New Delhi, India
05.2026 - Current
  • Oversee end-to-end IT security and infrastructure management of IGOT, the Government of India's flagship national learning platform serving millions of civil servants across ministries and departments.
  • Led vulnerability assessment and penetration testing (VAPT) initiatives, identifying and remediating security gaps across platform infrastructure to enhance overall security posture.
  • Architect and administer GCP-based cloud infrastructure, ensuring high availability, secure configuration, and compliance with government IT security standards across multi-cloud and on-premises environments.
  • Managed infrastructure and environment lifecycle, including provisioning, monitoring, patch management, and capacity planning on GCP, ensuring operational integrity and compliance.
  • Delivered incident trend dashboards and weekly threat intelligence briefings to senior leadership using Grafana and Kibana, supporting informed decision-making on security strategies.
  • Apply MITRE ATT&CK and Cyber Kill Chain frameworks to map adversary TTPs and prioritize defensive countermeasures.
  • Government of India's flagship national learning platform serving millions of civil servants across ministries and departments.
  • Core Technologies: GCP, Grafana, WIZ, VAPT, Team Leadership, Application Management

Senior Security Analyst

HCLTech
New Delhi, India
10.2024 - 05.2026
  • Managed 24x7 SOC operations with Devo SIEM, CrowdStrike EDR, and Siemplify SOAR, effectively triaging thousands of security events to enhance organizational threat detection.
  • Design and deploy SOAR playbooks automating alert triage, containment, and evidence collection, reducing analyst response time by an estimated 40%.
  • Execute full incident response lifecycle - detection, analysis, containment, eradication, and post-incident review - aligned with NIST SP 800-61.
  • Performed log correlation and behavioural analysis across multi-cloud and on-premises environments, identifying advanced persistent threat (APT) indicators to inform defensive strategies.
  • Delivered executive-level incident trend dashboards and weekly threat intelligence briefings, equipping senior management with actionable insights on emerging threats.
  • Apply MITRE ATT&CK and Cyber Kill Chain frameworks to map adversary TTPs and prioritize defensive countermeasures.
  • Core Technologies: Devo SIEM, CrowdStrike EDR, Siemplify SOAR, Threat Intelligence, MITRE ATT&CK, Incident Response

Senior Security Engineer

CIPL
New Delhi, India
07.2024 - 10.2024
  • Monitored enterprise security posture using Trellix XDR, RSA NetWitness SIEM, SOAR, Cloud WAF, NAC, and Radware DDoS Mitigation in real time.
  • Conducted OSINT-driven investigations into phishing campaigns, malware distribution networks, and suspicious IP infrastructure.
  • Executed vulnerability assessments via Rapid7 Insight VM, delivering risk-ranked remediation reports that informed client stakeholders' decisions.
  • Provided L2 escalation support and triaged complex multi-vector incidents while managing OEM TAC engagements to resolve critical platform issues.
  • Integrated newly procured security appliances into SIEM ecosystem, ensuring seamless operation and continuity.
  • Core Technologies: Trellix XDR, RSA NetWitness, Rapid7 Insight VM, Cloud WAF, Radware DDoS, OSINT, SOAR

Senior Security Analyst

Inspira Enterprise India
New Delhi, India
10.2023 - 06.2024
  • Administered RSA SIEM, SOAR, and Database Activity Monitoring (DAM) tools for large-scale BFSI clients with strict regulatory compliance requirements.
  • Investigated and escalated high-impact threats with detailed write-ups including root cause analysis, IOC extraction, and remediation guidance.
  • Managed phishing investigation workflows, including URL detonation, header analysis, attachment sandboxing, and user notification, to enhance threat detection and response.
  • Authored 50+ custom correlation rules, parser configurations, and interactive dashboards to surface high-fidelity security alerts.
  • Coordinated OEM patch management and device integration to ensure compliance and security across heterogeneous environments.
  • Mentored junior SOC analysts on triage methodologies and escalation procedures, increasing team efficiency and knowledge retention.
  • Core Technologies: RSA SIEM, SOAR, DAM, Threat Hunting, SIEM Content Creation, Phishing Analysis, OEM Coordination

Security Engineer

Sify Technologies
New Delhi, India
10.2022 - 10.2023
  • Implemented WAF rule sets and DDoS protection policies, safeguarding client web applications from volumetric and application-layer attacks.
  • Administered ArcSight ESM and RSA NetWitness for enterprise clients, overseeing log ingestion, connector upgrades, and rule tuning to enhance security visibility.
  • Led threat investigations covering malware execution chains, spear-phishing campaigns, and email spoofing with formal investigation reports.
  • Managed endpoint security integrations across Windows Server, Linux, Cisco, and Symantec Endpoint Protection environments.
  • Classified security alerts as true or false positives using contextual log correlation and threat intelligence enrichment.
  • Produced monthly SIEM health, performance, and SLA compliance reports for client review boards, ensuring alignment with security operational standards.
  • Core Technologies: ArcSight ESM, RSA NetWitness, WAF, DDoS Mitigation, Malware Analysis, Endpoint Security, Log Management

Security Analyst (AM BRO)

Axis Bank
New Delhi, India
09.2021 - 10.2022
  • Performed RSA SIEM log analysis and malware forensic investigations within a regulated banking environment subject to RBI cybersecurity guidelines.
  • Generated security metrics reports weekly, monthly, and quarterly for CISO and board-level risk discussions, enhancing informed decision-making.
  • Managed incident escalation workflows, ensuring timely resolution within SLA thresholds and maintaining comprehensive documentation of the incident lifecycle for accountability.
  • Identified and documented network vulnerabilities, contributing findings to organization's risk register to inform risk management strategies.
  • Administered analyst shift scheduling and roster management for a 24x7 SOC team.
  • Core Technologies: RSA SIEM, Malware Forensics, Vulnerability Assessment, Report Generation, Shift Management

Security Analyst (L1 SOC)

Genesis Infocom Pvt. Ltd.
Bangalore, India
06.2018 - 05.2021
  • Executed Level 1 incident triage and escalation in a 24x7 SOC, managing high-volume ticket queues with SLA-driven prioritization.
  • Analysed SIEM-generated alerts, validated threat indicators, and coordinated with internal IT teams for remediation.
  • Identified recurring threat patterns and proposed targeted mitigations to L2 analysts and SOC manager, enhancing incident response strategies.
  • Onboarded 20+ devices to SIEM platform, configuring log sources, parsing data, and mapping initial rules to enhance monitoring capabilities.
  • Contributed to SOC playbook documentation and led phishing simulation exercises to elevate end-user security awareness.
  • Core Technologies: SIEM Operations, Incident Triage, SLA Management, Device Onboarding, Playbook Development

Education

Bachelor of Technology - Computer Science and Engineering

Punjab Technical University
06-2014

Senior Secondary, Class XII - English Medium

CBSE
01-2009

Secondary, Class X - English Medium

CBSE
01-2007

Skills

  • GCP Infrastructure Security
  • Multi-cloud environments
  • Kibana
  • AWS Security Fundamentals
  • Vulnerability assessment
  • Incident management
  • SOC management
  • Incident Coordination
  • Incident Response
  • Threat Hunting
  • Playbook development
  • Alert Orchestration
  • XSOAR
  • NIST SP 800-61
  • MITRE ATT&CK
  • Cyber Kill Chain
  • NIST CSF
  • Risk Ranking
  • Vulnerability assessment
  • Log Ingestion
  • Log Parsing
  • Correlation Rule Authoring
  • IPS/IDS
  • WAF
  • NAC
  • CrowdStrike Falcon
  • SentinelOne
  • Symantec Endpoint Protection
  • RSA NetWitness
  • ArcSight ESM
  • Devo
  • Trellix XDR
  • Splunk
  • QRadar
  • Siemplify
  • Rapid7 Insight VM
  • Patch Management
  • IOC Enrichment
  • TIP Integration
  • DFIR
  • OWASP
  • Security Metrics
  • Grafana
  • Vulnerability assessment
  • Mentorship
  • Team management
  • IT security

Certification

  • Certified Ethical Hacker (CEH), EC-Council, 10/01/25
  • Certified Information Security Manager (CISM), ISACA, 01/01/27
  • EC-Council Certified Incident Handler (ECIH), EC-Council, 11/01/26

Accomplishments

  • Currently leading IT security and GCP cloud infrastructure operations for iGOT (Karmayogi Bharat), a flagship Government of India learning platform serving millions of users.
  • Mitigated 100+ high-severity incidents by engineering SOAR playbooks and deploying CrowdStrike EDR containment actions, reducing average incident closure time by approximately 30%.
  • Reduced analyst response time by an estimated 40% through design and deployment of automated SOAR playbooks for alert triage, containment, and evidence collection.
  • Authored 200+ correlation rules, parsers, and dashboards across ArcSight, RSA NetWitness, and Devo, significantly improving detection fidelity and analyst efficiency.
  • Onboarded and managed 50+ heterogeneous security devices, including firewalls, IPS/IDS, WAF, NAC, and DDoS mitigation platforms, with zero data-loss log ingestion.
  • Served as L2/L3 escalation authority for multiple Fortune 500 accounts, maintaining full SLA compliance and earning repeated client commendations.
  • Led proactive threat-hunting campaigns using MITRE ATT&CK TTPs, uncovering latent adversarial activity before operational impact.

Languages

  • English, Professional Proficiency
  • Hindi, Native Proficiency

Awards

  • Security Champion Award - Inspira Enterprise India, recognized for exceptional incident detection and response performance.
  • Certificate of Excellence - HCLTech, awarded for outstanding SOC operations contribution and client satisfaction.
  • Best Analyst Recognition - Sify Technologies, honored for superior threat investigation accuracy and report quality.

Timeline

Manager - IT Security and Cyber Security

Karmayogi Bharat (IGOT)
05.2026 - Current

Senior Security Analyst

HCLTech
10.2024 - 05.2026

Senior Security Engineer

CIPL
07.2024 - 10.2024

Senior Security Analyst

Inspira Enterprise India
10.2023 - 06.2024

Security Engineer

Sify Technologies
10.2022 - 10.2023

Security Analyst (AM BRO)

Axis Bank
09.2021 - 10.2022

Security Analyst (L1 SOC)

Genesis Infocom Pvt. Ltd.
06.2018 - 05.2021

Bachelor of Technology - Computer Science and Engineering

Punjab Technical University

Senior Secondary, Class XII - English Medium

CBSE

Secondary, Class X - English Medium

CBSE
ANKIT KUMAR