$ whoami
John Jebas
Enterprise SOC Tier 1 & 2 Security Analyst with 1 year 5 months of hands-on operations experience at TVS Electronics. Specializing in Microsoft Sentinel SIEM detection architecture, KQL threat hunting heuristics, endpoint containment with Bitdefender EDR, and OWASP-aligned vulnerability assessment/penetration testing (VAPT). Splunk certified and Certified Ethical Hacker (CEH) certified.
- 1.5 yrs
- SOC Experience
- Tier 1&2
- Analyst Level
- MITRE
- ATT&CK Aligned
- OWASP
- Top 10 Testing
Live Global Threat Intelligence
● Real-time FeedActive Incident Feed
SENTINEL SIEMDetect
SIEM · KQL · MITREArchitect and tune analytics rules across Microsoft Sentinel with hypothesis-driven KQL hunting queries. Map detections to MITRE ATT&CK tactics, reduce alert fatigue via dynamic threshold calibration, and achieve sub-5-minute mean-time-to-detect (MTTD) across Windows, Linux, identity and network log sources.
- 92% alert coverage rate
- KQL rule authoring
- Sub-5min MTTD
- MITRE-mapped detections
Respond
IR · EDR · SOARDrive structured incident lifecycle management from initial triage to root cause analysis and post-incident review. Execute endpoint isolation, credential resets, and phishing campaign containment using Bitdefender EDR and Logic Apps SOAR playbooks. Deliver evidence-backed closure reports with NIST SP 800-61 alignment.
- Full lifecycle IR
- Endpoint containment
- SOAR playbooks
- NIST 800-61 aligned
Harden
VAPT · CVE · OWASPConduct authenticated OWASP Top 10 web application assessments and CVSS v3.1-scored vulnerability scanning with Burp Suite Pro and Nessus. Deliver prioritised remediation reports with reproducible PoCs, exploit validation, and developer-ready fix guidance aligned to business risk exposure.
- OWASP Top 10 testing
- CVSS v3.1 scoring
- Burp Suite Pro
- Validated PoC delivery
Experience
Cyber Security Analyst — SOC Tier 1 & 2
TVS Electronics Ltd. · Chennai, Tamil Nadu · March 2025 – Present
Embedded within a 24×7 enterprise Security Operations Center at TVS Electronics, operating across the full defensive lifecycle — from real-time SIEM alert triage and KQL-driven threat hunting in Microsoft Sentinel to endpoint isolation via Bitdefender EDR, SOAR playbook automation, CVSS-ranked vulnerability management and OWASP-aligned web application penetration testing. Responsible for both detection engineering and incident response closure reporting.
SIEM Monitoring & Threat Hunting
Front-line monitoring of enterprise log sources in Microsoft Sentinel, turning raw telemetry into actionable incidents.
- Triaged daily alert queues across Windows, Linux, firewall, identity and endpoint log sources, classifying true/false positives with documented rationale.
- Wrote and iterated KQL hunting queries over SecurityEvent, SigninLogs and DeviceEvents to surface anomalies that no existing rule covered.
- Correlated multi-source events into single incidents to remove duplicate noise and give responders one timeline per intrusion attempt.
- Microsoft Sentinel
- KQL
- Log Analytics
- Azure AD Logs
⬡ TA0001 Initial Access · TA0006 Credential Access
Detection Engineering & Automation
Improved detection quality by tuning what fires, when it fires, and what happens automatically afterwards.
- Authored and tuned Sentinel analytics rules, adjusting thresholds, entity mappings and suppression windows to cut alert fatigue without losing coverage.
- Built automation playbooks for repetitive triage steps — enrichment, entity lookup and analyst notification — shortening time-to-first-action.
- Mapped detections to MITRE ATT&CK techniques so coverage gaps were visible and prioritised rather than assumed.
- Analytics Rules
- Logic Apps Playbooks
- MITRE ATT&CK
- SOAR Concepts
⬡ Detection coverage mapping
Incident Response & Investigation
Owned incidents end-to-end from detection through containment, remediation and closure reporting.
- Investigated phishing campaigns — header analysis, URL and attachment detonation, affected-user scoping and mailbox-level cleanup.
- Handled brute-force and impossible-travel sign-in incidents: validated source IP reputation, confirmed compromise, forced credential resets.
- Documented each incident with timeline, root cause, impact and remediation actions, and fed findings back into detection tuning.
- Sentinel Incidents
- VirusTotal
- AbuseIPDB
- Email Header Analysis
⬡ TA0043 Recon · TA0011 Command & Control
Vulnerability Assessment & Penetration Testing
Offensive-side testing of web applications and internal systems, reported with reproducible evidence.
- Performed authenticated and unauthenticated web app testing against the OWASP Top 10 — SQL injection, XSS, broken access control, auth and session flaws.
- Validated scanner output manually to eliminate false positives before anything reached the remediation backlog.
- Delivered VAPT reports with reproduction steps, CVSS-scored severity, business impact and concrete developer-facing fixes.
- Burp Suite Pro
- OWASP ZAP
- Nmap
- Nessus
- Kali Linux
⬡ OWASP Top 10 aligned
Vulnerability & Patch Management
Continuous assessment of the endpoint and server estate with risk-ranked remediation tracking.
- Ran scheduled authenticated scans across Windows and Linux endpoints, tracking newly introduced CVEs between cycles.
- Prioritised remediation using CVSS severity combined with asset exposure and exploit availability rather than raw score alone.
- Coordinated with IT teams on patch cycles and re-validated closure with follow-up scans.
- SecPod SanerNow
- Nessus
- CVE / CVSS
- Patch Cycles
⬡ Exposure reduction
Endpoint Detection & Response
Day-to-day ownership of endpoint protection posture and malware investigation across the estate.
- Investigated EDR detections — process trees, parent-child anomalies, persistence artefacts and suspicious script execution.
- Contained compromised hosts through isolation and blocked malicious hashes and processes across the fleet.
- Reviewed policy exclusions and endpoint health to keep coverage complete and false positives low.
- Bitdefender EDR
- Windows Event Logs
- Process Analysis
- Host Isolation
⬡ TA0002 Execution · TA0003 Persistence
Threat Intelligence & Reporting
Enriched investigations with external context and turned technical findings into readable reporting.
- Validated IPs, domains, URLs and file hashes against VirusTotal and open-source threat intel before blocking or escalating.
- Maintained IOC context for recurring campaigns so repeat activity was recognised immediately.
- Produced incident and assessment reports for both technical responders and non-technical stakeholders.
- VirusTotal
- OSINT Feeds
- IOC / IOA
- Reporting
⬡ Enrichment & attribution
Technical Skills
SIEM & Threat Detection
Daily driver for 24x7 monitoring — building, tuning and hunting across Microsoft Sentinel log sources.
- ▸Authored KQL analytics rules across sign-in, endpoint and firewall tables with tuned thresholds to cut false positives.
- ▸Ran hypothesis-driven hunts on anomalous authentication, lateral movement and persistence patterns.
- ▸Built workbooks and scheduled queries for daily SOC shift handover and management reporting.
- Sentinel
- KQL
- Log Analytics
- Workbooks
- Alert Triage
- Playbooks
Framework · MITRE ATT&CK detection coverage mapping
VAPT & Security Testing
Web and network assessments end-to-end — recon, exploitation validation, and developer-ready remediation reporting.
- ▸Performed authenticated and unauthenticated web app tests covering injection, access control and session flaws.
- ▸Validated scanner output manually to eliminate false positives before raising findings.
- ▸Scored issues with CVSS v3.1 and delivered reproducible PoCs with fix guidance to engineering teams.
- Burp Suite
- Nessus
- Nmap
- OWASP ZAP
- SanerNow
- CVSS v3.1
Framework · OWASP Top 10 / OWASP Testing Guide
EDR & Incident Response
Endpoint containment and full incident lifecycle — from first alert to root cause and closure notes.
- ▸Investigated endpoint detections through process trees, parent-child anomalies and persistence artifacts.
- ▸Isolated compromised hosts, killed malicious processes and coordinated reimaging with IT.
- ▸Documented incidents with timeline, impact, root cause and preventive actions.
- Bitdefender EDR
- IOC / IOA
- VirusTotal
- Sandboxing
- SOAR Concepts
Framework · NIST SP 800-61 incident handling lifecycle
Networking & Platforms
Protocol-level understanding that underpins traffic analysis, log interpretation and detection accuracy.
- ▸Analysed packet captures and firewall logs to confirm C2 beaconing and data exfiltration attempts.
- ▸Correlated Windows event IDs (4624/4625/4688/7045) into detection logic.
- ▸Reviewed DNS and proxy telemetry for tunnelling and newly registered domain access.
- TCP/IP
- DNS
- HTTP/HTTPS
- Windows
- Kali Linux
- Wireshark
- Firewalls
Framework · Cyber Kill Chain traffic-stage analysis
Scripting & Automation
Query and script work to remove manual toil from triage, enrichment and reporting workflows.
- ▸Wrote reusable KQL functions for repeated triage lookups across analysts.
- ▸Used Python scripts for bulk IOC enrichment and report data formatting.
- ▸Automated recurring evidence collection steps with shell one-liners.
- KQL
- SQL
- Python
- Bash
- REST APIs
- Automation Playbooks
Framework · SOC toil reduction / analyst enablement
MITRE ATT&CK Matrix Detection Coverage Console
Initial Access
The adversary is trying to get into your network via perimeter vectors.
OfficeAttachmentDeliveryEvents
| where FileExtension in ("exe", "lnk", "vbs", "ps1")
| where ThreatTypes has "Malware" or ThreatTypes has "Phish"
| project Timestamp, SenderAddress, RecipientAddress, FileNameCertifications & Education
Vesting Credential Signatures
- Completed
Certified Ethical Hacker (CEH)
EC-Council
Certified Cybersecurity Educator Professional (CCEP)
Red Team Leaders
Security Operations and Defense Analyst
Splunk
Understanding Threats and Attacks
Splunk
Cybersecurity Essentials
Cisco Networking Academy
SanerNow Cyber Hygiene Platform Training
SecPod
Education
B.Tech — Computer Science and Engineering
Dr. M.G.R. Educational and Research Institute, Chennai
2020 – 2024 · CGPA 7.91
Beyond Work
- Active on TryHackMe and Hack The Box — hands-on labs and CTF challenges.
- Focused on SOC operations, threat hunting, incident response and cloud security.
Projects
IFLEX TRAX 1.7 — Facebook-Style User Registration System
Collaboratively developed a Facebook-style user registration system with secure signup, form validation, database integration and a responsive interface.
- Python
- Django
- MySQL
- HTML
- CSS
- JavaScript
$ contact --open
Open to SOC & Security Analyst roles
© 2026 John Jebas · Chennai, India