Vinay Raina

DevOps Engineer

Delhi, India11 yrs 1 mo experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Expert in Incident Response and Digital Forensics.
  • Proficient in leveraging advanced cybersecurity tools.
  • Strong collaboration with cross-functional teams.
Stackforce AI infers this person is a Cybersecurity Analyst specializing in Incident Response and Digital Forensics.

Contact

Skills

Core Skills

Incident ResponseDigital ForensicsCyber Threat HuntingSecurity Incident ResponseThreat AnalysisSecurity MonitoringIt Infrastructure Management

Other Skills

SplunkCyber Kill ChainIncident Response Plan (IRP)Threat IntelligenceEmail SecurityPalo Alto Cortex XSOARThreat HuntingCyber Threat IntelligenceFireEye's RedlineMITRE ATT&CK FrameworkAWS GuardDutyAWS CloudTrailAzure ATPReportingPhishing Simulation

About

Experienced Senior Incident Response and Digital Forensics Analyst specializing in leveraging frameworks like the Cyber Kill Chain and Incident Response Plan (IRP) to swiftly mitigate cyber threats. Proficient in utilizing advanced tools such as Splunk for creating use cases, developing dashboards, and conducting log analysis to detect anomalies, IOCs (Indicators of Compromise), and minimize search time. Skilled in managing Security Information and Event Management (SIEM) systems and Security Orchestration, Automation, and Response (SOAR) platforms like Palo Alto Cortex XSOAR. Demonstrated ability to effectively handle breaches and conduct comprehensive investigations using tools like FireEye's Redline. Experienced in crafting detailed Incident Response Plans (IRPs) and collaborating with cross-functional teams to ensure swift and effective incident response. Passionate about staying updated with the latest cybersecurity trends, including Threat Intelligence and Threat Hunting, to proactively identify and mitigate security risks.

Experience

11 yrs 1 mo
Total Experience
5 yrs 6 mos
Average Tenure
10 yrs 9 mos
Current Experience

Mckinsey & company

4 roles

Senior Incident Response Analyst

Promoted

Jan 2024Present · 2 yrs 5 mos · On-site

  • Proficient in handling diverse cyber incidents, including phishing attacks and various malware types such as ransomware, trojans, worms etc.
  • Adept in utilizing the Cyber Kill Chain and Incident Response Plan (IRP) framework.
  • Skilled in Splunk for creating use cases, developing dashboards, and conducting log analysis.
  • Experienced in developing robust data models and lookups in Splunk.
  • Collaborates effectively with Managed Detection and Response (MDR) Endpoint Detection and Response (EDR) teams.
  • Proficient in conducting comprehensive digital forensics investigations using FireEye's Redline tool.
  • Ensures quality of security incidents handled by Level 1 (L1) and Level 2 (L2) teams.
  • Crafts detailed Incident Response Plans (IRPs) for high and critical security incidents.
  • Conducts Dry Runs for new use cases and refines IRP plans.
  • Collaborates with legal teams on cases related to client breaches and Personally Identifiable Information (PII) data leaks.
  • Manages email security using Email Security Appliances (ESA) such as Proofpoint, Phishlabs, and Cofense.
  • Implements automation of use cases using Palo Alto Cortex XSOAR platform.
  • Proficient in leveraging Threat Intelligence to enhance incident response and proactively identify emerging threats.
  • Skilled in conducting proactive Threat Hunting activities to detect and mitigate potential security threats before they escalate.
SplunkCyber Kill ChainIncident Response Plan (IRP)Threat IntelligenceEmail SecurityPalo Alto Cortex XSOAR+2

Security Operations Center (SOC) Analyst

Promoted

Oct 2019Dec 2023 · 4 yrs 2 mos · On-site

  • Spearheaded day-to-day SOC operations, managing a wide array of incidents with agility and efficiency.
  • Utilized FireEye's Redline tool for conducting comprehensive digital forensics during investigations, ensuring thorough analysis and effective resolution of security incidents.
  • Generated monthly high/critical incident and vulnerability reports, with a keen focus on endpoint protection and cloud security metrics to enhance organizational resilience.
  • Conducted Dry Runs and crafted detailed Incident Response Plans (IRPs) for new Use cases, ensuring readiness and effectiveness in responding to emerging threats.
  • Produced detailed Email Security metrics reports to identify trends and patterns, enabling proactive measures to enhance email security posture.
  • Managed AWS CloudTrail and GuardDuty alerts, as well as Defender ATP, Azure ATP, & O365 for robust threat detection and response capabilities.
  • Leveraged the MITRE ATT&CK framework for comprehensive threat analysis and classification, ensuring thorough understanding and effective response to cyber threats.
  • Partnered with the Threat Hunt team to assess monthly findings and develop actionable plans to mitigate emerging threats.
  • Collaborated closely with the Cyber Risk team to produce Monthly Risk Mapping reports, providing valuable insights into potential threats and vulnerabilities.
  • Demonstrated a commitment to continuous improvement by fine-tuning and automating use cases, leveraging the MITRE ATT&CK framework for comprehensive threat analysis and classification.
  • Regularly organized Table Top activities with the team & entities to simulate real-world scenarios and enhance incident response readiness.
  • Cultivated strong client relationships and collaborated closely with them to reduce false positives, noise, and prioritize critical cases effectively.
  • Played a key role in developing response plans for security incidents, working closely with the legal team on client breach & PII Data leak cases.
FireEye's RedlineEmail SecurityMITRE ATT&CK FrameworkAWS GuardDutyAWS CloudTrailAzure ATP+2

Junior Security Operations Analyst

Promoted

Oct 2017Sep 2019 · 1 yr 11 mos · On-site

  • Implemented robust monitoring of critical system security and changes in sensitive controls, promptly taking administrative actions and reporting irregularities.
  • Conducted comprehensive network vulnerability assessments to identify vulnerabilities and created remediation plans to mitigate potential risks.
  • Established and maintained security risk metrics to track ongoing effectiveness and ensure continuous improvement of security measures.
  • Managed email security using Email Security Appliances (ESA) such as Proofpoint and Cofense to protect against email-based threats.
  • Conducted thorough security assessments for new tools and applications to ensure they meet security standards and requirements.
  • Orchestrated Phishing Simulation activities in collaboration with the Risk team to assess and enhance the organization's resilience to phishing attacks.
  • Actively participated in Threat Hunting initiatives, leveraging threat intelligence and advanced techniques to proactively identify and mitigate potential security threats.
  • Responded to basic security incidents, ensuring timely resolution and mitigation of risks to the organization's assets and data.
Email SecurityPhishing SimulationSecurity AssessmentsSecurity Monitoring

Information Technology Operations Specialist

Jun 2015Sep 2017 · 2 yrs 3 mos · On-site

  • Monitored all the critical assets of the firm including servers, databases, network
  • devices, emails and applications and collaborated with the L2 and L3 teams for alerting and remediation.
IT Infrastructure ManagementInfrastructure MonitoringReporting

Accenture

Operations Executive

Jan 2015May 2015 · 4 mos · Gurgaon, India

High-Pressure SituationsDocumentationInterpersonal Skills

Education

Motivational Pathway

Bachelor’s Degree — Electronics and Communications Engineering

Jan 2010Jan 2014

Rainbow English Sr Sec School

Bachelor of Technology (B.Tech.) — Electronics and Communications Engineering

Jan 2000Jan 2010

Stackforce found 100+ more professionals with Incident Response & Digital Forensics

Explore similar profiles based on matching skills and experience