Himanshu Gupta

CEO

Shimla Rural, Himachal Pradesh, India12 yrs experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Expert in Cybersecurity and Threat Detection.
  • Developed innovative frameworks for security investigations.
  • Proven track record in building security programs.
Stackforce AI infers this person is a Cybersecurity expert with extensive experience in threat detection and incident response.

Contact

Skills

Core Skills

CybersecuritySecurity Incident Response

Other Skills

AIMLAnalytical SkillsAnomaly DetectionAzure DatabricksAzure DevOpsAzure KustoBig Data AnalyticsCOSMOSCross-team CollaborationCyber Threat Hunting (CTH)Cyber Threat Intelligence (CTI)Cybersecurity HuntingCybersecurity Incident ManagementCybersecurity Incident ResponseDashboard

Experience

Microsoft

6 roles

Principal Security Researcher

Promoted

Mar 2025Present · 1 yr

Senior Security Engineer

Apr 2021Mar 2025 · 3 yrs 11 mos

  • LLM Strategist for SOC: Investigation, Detection, and Hunt
  • Working on Hunt@Scale framework based on team requirement. The idea is to onboard hunt queries quickly and store hunting results with user behaviors so that in long term we can create timeline and identify patterns. Completed POC stage and currently onboarding more hunting hypothesis.
  • Working on IaM (Identity Anomaly Detector) which is based on UEBA. The idea is to generate investigative points/features based on user daily activity and the flag anomalies. The backbone of this idea is our core knowledge in Tenant investigation and security incidents knowledge.
  • On day-to-day basis we do investigations of customer tenant compromise. Identify fraud vs abuse scenarios and report to respective teams.
  • Investigation in security incidents and pen test activities. Identified critical information and shared same with service teams.
  • Part of hunting in Azure DevOps to identify risks in Supply Chain.
TrainingSecurity ResearchAnalytical SkillsAIMLEnd to End DeliveryCross-team Collaboration+33

Senior Security Analyst

Promoted

Mar 2020Mar 2021 · 1 yr

  • Integral part in reviewing and providing mission critical feedback for in-house next generation SIEM (Project X) Analytics engine, ADO detection deployment pipeline, detection deployment platform like RxKQL, Kusto Detection Queries and ARIS from Detection program perspective.
  • Worked on an Alert Scoring model to increase fidelity of alerts. Worked upon end-to-end modular architecture which can be easily integrated with any platform used by SOC. Idea is to assign weighted score to alert in near real time based on deterministic investigative points which will help analyst to decide fidelity of alerts and low risk of missing malicious activity.
  • Experience in performing exploratory analysis on customer service telemetry and proposed monitoring scenarios out of it.
TrainingSecurity ResearchAnalytical SkillsAIMLEnd to End DeliveryCross-team Collaboration+35

Escalation Security Analyst II

Sep 2018Feb 2020 · 1 yr 5 mos

  • Built and operationalize Threat Hunting program from scratch for one of the complex environments involving more than one Lac Windows Servers including Physical and Cloud Based Machines.
  • Worked in Collaboration with Data Science Teams to Provide Use Cases from Security Monitoring Perspective and performed testing of newly deployed Data Science Models and further facilitated onboarding the Same to SOC Monitoring.
  • Involved in development of one of the Market Leading EDR Technology Windows ATP. Provided analysis related Requirements to ATP Product Group, tested their features and Provided Feedbacks, Suggested New Functionalities, created some of Advance Threat Hunting Queries.
  • Solving Information Security Problems using Data Science & Machine Learning. Evaluated TSR Model on Windows (Logon Anomaly, Process command line switch) and Zeek (Data Exfiltration) Events to detect adversaries and tried to use NLP to detect command line switch-based anomaly.
TrainingSecurity ResearchAnalytical SkillsEnd to End DeliveryCross-team CollaborationProblem Solving+28

Security Analyst II

Promoted

Sep 2017Aug 2018 · 11 mos

  • Expertise in Identifying Risks and working on Remediation of Risk across Company.
  • Part of Detection Program (Identifying new Detection Opportunities, Detection based on Customer Requirements, Detection Onboarding, Detection Testing), Threat Hunting and Security Operations for Microsoft Cloud and AI Security Team that is responsible of monitoring infrastructure of some of the critical Microsoft Infrastructure like Windows Build, Windows Update, Signing Environment, Xbox and Surface.
  • Experience in kick starting Detection Program from Scratch by adopting Kill Chain Model and ATT&CK MITRE Framework to detect advance Threats (APTs) and new attack techniques as the foundation of the detection program.
TrainingSecurity ResearchAnalytical SkillsCross-team CollaborationMicrosoft Power AppsSecurity Incident & Event Management+17

Security Analyst

Sep 2015Aug 2017 · 1 yr 11 mos

  • Expertise in handling Security Incidents involving Intrusion Detection, Digital Forensics, IOC Hunting and have been part of Response Team in some of APT Scenarios.
  • Hands on experience in Host & Network Level Forensics. Have Leveraged Tools like KANSAAS, X-Ways in my Investigations.
  • Experience of working in collaboration with Red Teams, Purple Teams and Green Teams to achieve the purpose of the exercise.
  • Experience in alert Investigation on Arcsight.
Security ResearchAnalytical SkillsCross-team CollaborationMicrosoft Power AppsSecurity Incident & Event ManagementCybersecurity+11

Symantec

3 roles

Cyber Security SOC Analyst

Oct 2013Aug 2015 · 1 yr 10 mos · Chennai, Tamil Nadu, India

  • Expertise in analyzing security alerts on in house SIEM tool and report same to customers based on severity.
  • Integral part of implementation of Social Media Monitoring using Scumblr for our customers to scrape out the leaked/compromised information from social media/deep web.
  • Extensive knowledge in analyzing the logs of multiple devices like IDS/IPS, Network & Application Firewall, SEP, Anti-Virus, FireEye, EDR etc.
  • Experience in resolving customer requests related to security alerts and provide security related assistance over call.
  • Experience in creating reports with infographics for latest security trends and gather generic reports based on customer business segments.
Security ResearchAnalytical SkillsCross-team CollaborationProblem SolvingProof of ConceptSecurity Incident & Event Management+8

Cyber Security Analyst

Jul 2013Sep 2013 · 2 mos · Chennai, Tamil Nadu, India

Security ResearchAnalytical SkillsCross-team CollaborationCybersecurityResearch

Cyber Security Intern

Dec 2012Jun 2013 · 6 mos · Chennai, Tamil Nadu, India

Security ResearchAnalytical SkillsCross-team CollaborationCybersecurityResearch

Education

IIIT Hyderabad

Foundation degree — Artificial Intelligence and Machine Learning

Jan 2018May 2018

SRM IST Chennai

Master of Technology - MTech — Information Security And Computer Forensics

Jun 2011May 2013

Punjab Technical University

Bachelor of Technology - BTech — Computer Science and Engineering

Jun 2006May 2010

Stackforce found 100+ more professionals with Cybersecurity & Security Incident Response

Explore similar profiles based on matching skills and experience