Sudheer Mattaparthi

DevOps Engineer

Hyderabad, Telangana, India14 yrs 7 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Over 13 years of experience in cybersecurity.
  • Expertise in SIEM and SOAR platforms.
  • Proven track record in security tool implementation.
Stackforce AI infers this person is a Cybersecurity expert with extensive experience in SIEM, cloud security, and data loss prevention.

Contact

Skills

Core Skills

SiemSecurity OperationsVulnerability ManagementCloud SecurityData Loss PreventionWeb Application Security

Other Skills

WIZGoogle ChronicleSymantec DLPTripwireNessusCisco FMCStealthwatchCrowdStrikeLog ManagementSplunk ESAmazon GuardDutyQualysSymantec VIPCA PAMThreat Detection

About

Principal Cyber Security Engineer with 13+ years of experience in security engineering, security operations, and security tool implementation & administration. Proven expertise in SIEM & SOAR platforms, endpoint security, cloud security, WIZ CSPM, DLP, CASB, IDS, PAM, FIM, VAPT, and web application security testing. SKILLS: • SIEM & SOAR: Splunk Enterprise Security, Google Secops (Chronicle) & Demisto • Endpoint Security : Microsoft Defender for Endpoint and CrowdStrike Falcon • Data Loss Prevention: Symantec DLP • CASB: Microsoft Defender for Cloud • IDS & NAC: Cisco Firepower & Palo Alto and Cisco ISE (BYOD) • Vulnerability Assessment: Tenable Nessus, QualysGuard and McAfee Vulnerability Manager • File Integrity Monitoring: Tripwire Enterprise • Other Security Tools: Cisco Stealthwatch and Tufin Firewall Manager • CSPM/Cloud Security: WIZ, AWS Security Hub, GuardDuty, Inspector

Experience

14 yrs 7 mos
Total Experience
4 yrs 10 mos
Average Tenure
4 yrs 11 mos
Current Experience

Entain india

2 roles

Principal Security Engineer

Promoted

Dec 2025Present · 4 mos · Hyderabad, Telangana, India

Senior Cyber Security Engineer

May 2021Dec 2025 · 4 yrs 7 mos · Hyderabad, Telangana, India

  • Managed enterprise-wide security tools including WIZ, Google Chronicle, Symantec DLP, Tripwire, Nessus, Cisco FMC, Stealthwatch, CrowdStrike etc.
  • Deployed and integrated Google Chronicle SIEM across hybrid environments (on-prem and cloud), enabling centralized log collection and real-time threat detection.
  • Investigated and resolved log parsing and UDM mapping issues to ensure accurate normalization and correlation of security events across diverse log sources.
  • Designed and built custom dashboards to monitor log availability and the health of security tools to ensure service availability.
  • Onboarding new data sources into Chronicle, validating end-to-end event ingestion and ensuring log completeness.
  • Installed & configured IDS sensors in new DCs and set up TAP interfaces for NW traffic inspection.
  • Coordinated CrowdStrike agent upgrades by identifying outdated versions via Falcon console and collaborating with IT support teams.
  • Administered Tripwire Enterprise for file integrity monitoring (FIM), including agent deployments, console upgrades, and policy tuning.
WIZGoogle ChronicleSymantec DLPTripwireNessusCisco FMC+4

Tata consultancy services

3 roles

Senior Security Engineer

Promoted

Jun 2019May 2021 · 1 yr 11 mos · On-site

  • Built & Onboarded SIEM: Architected and deployed Splunk ES (search heads, indexers, forwarders, clustering, DB Connect) and onboarded logs from Windows/Unix servers plus network infrastructure (firewalls, IPS, proxies, load balancers, WAFs).
  • Threat Detection & Automation: Developed and tuned custom Splunk ES correlation rules; integrated Amazon GuardDuty findings for continuous, automated threat detection and 24/7 SOC monitoring.
  • Vulnerability Management: Deployed and managed Qualys scanners on-premises and Trend Micro Deep Security on AWS EC2 to ensure comprehensive vulnerability coverage.
  • Authentication & Access Control: Implemented Symantec VIP for MFA and CA Privileged Access Manager to enforce strict, auditable server access controls.
  • Conducted in-depth investigations of external cyberattacks, insider threats, and potential security breaches, ensuring accurate threat identification.
  • Managed escalations of high-priority cybersecurity incidents, coordinating with cross-functional teams to ensure swift containment and resolution.
Splunk ESAmazon GuardDutyQualysSymantec VIPCA PAMSIEM+1

Cyber Security Engineer

Nov 2017May 2019 · 1 yr 6 mos · On-site

  • Integrated Windows, Unix, network, firewall, proxy, load balancer, and DB logs into Splunk using Universal Forwarders and syslog servers for centralized security monitoring.
  • Connected Splunk with vulnerability management tools and email security appliances to enhance visibility and automate correlation of security events.
  • Built and fine-tuned custom Splunk correlation rules to detect and respond to cyber threats, supporting real-time incident response and investigations.
  • Leveraged CASB solutions for log integration from proxies/firewalls and cloud apps (Snow, Salesforce, Box, O365) via APIs; implemented compliance and legal discovery policies.
  • Deployed Windows Defender ATP agents for endpoint protection and advanced threat detection.
SplunkCASBWindows Defender ATPSIEMCloud Security

DLP Engineer

Jan 2014Oct 2017 · 3 yrs 9 mos · On-site

  • Deployed Symantec Web DLP software on production servers for Switzerland largest bank.
  • Responsible for enabling TLS interception at proxy and follow up with infrastructure team for deploying the TLS certificates on the end user machines to intercept the HTTPS traffic at proxy.
  • Enabled ICAPs protocol to securely transmit user traffic from Proxy to DLP servers for inspection.
  • Monitored & prevented sensitive data leakage over HTTP, HTTPS, and FTP traffic using Web DLP.
  • Experienced in upgrading WEB DLP, Endpoint DLP and Email DLP from 12.5 to 14.0.
  • Experienced in troubleshooting offline and disconnected DLP agents.
  • Proficient in creating DLP policies for endpoint, email, web, and storage.
Symantec DLPTLS InterceptionDLP PoliciesData Loss Prevention

Secureyes

Cyber Security Analyst

Jun 2011Dec 2013 · 2 yrs 6 mos · New Delhi, Delhi, India

  • Conducted OWASP-based web application security testing, including threat profiling, manual penetration testing, and vulnerability identification for multiple clients.
  • Prioritized and documented security findings with detailed risk categorizations, delivering reports and presentations to stakeholders.
  • Collaborated with development teams to demonstrate vulnerabilities (e.g., SQLi, XSS, CSRF, Broken Access Controls) and guided them on mitigation strategies.
  • Conducted vulnerability assessments on servers and network devices using Nessus, including asset validation, scanning profile creation, and prioritization based on risk.
  • Analysed and removed false positives, communicated findings to project teams, and provided actionable remediation guidance.
  • Performed rescans post-remediation to verify closure and ensured consistent reporting and compliance.
OWASPNessusPenetration TestingWeb Application Security

Education

Andhra University

Master of Computer Applications (MCA) — Computer Science

Jan 2007Jan 2010

Andhra University

Bachelor of Science - BSc

Jan 2004Jan 2007

Stackforce found 100+ more professionals with Siem & Security Operations

Explore similar profiles based on matching skills and experience