Feb 2026 — Present · Mumbai
Comtel Infosystem Private Limited
SOC Team Lead
- Lead and manage a SOC team of 10 analysts supporting multiple brokerage clients in a high-volume security environment.
- Oversee end-to-end SOC operations — SIEM, EDR, and event analysis across diverse security tools.
- Coordinate SIEM operations: log onboarding, use-case development, and integration of new devices.
- Develop and maintain TOML-based detection rules to expand threat detection coverage.
- Built a dedicated SOC room from scratch — infrastructure, tooling, and workflow design.
- Perform SOC efficacy assessments aligned with SEBI CSCRF, plus VA/CA for supporting infrastructure.
- Drive alert-noise reduction initiatives across SIEM/EDR platforms, cutting false positives by 40-45%.
- Cut client onboarding timeline from 4 weeks to 1 week by streamlining integration and readiness workflows.
- Sustain SLA and response-time commitments under a lean team structure by prioritizing automation and alert-fidelity improvements — an active focus area while scaling the team.
- Own vendor relationships for SIEM/EDR platforms and contribute to SOC tooling budget planning, resolving escalations directly with vendors.
- Maintain active engagement with a Europe-based Event Analysis Tool vendor and multiple Threat Intelligence vendors — authoring product-focused technical blogs and continuously evaluating emerging tools.
- Designed and deliver a structured 15-day analyst training program (weekly cadence) covering escalation protocols and threat-hunting fundamentals — 6 analysts trained to date.
- Contribute to platform rollout initiatives through vendor coordination and rollout planning, staging evaluation environments alongside the dedicated Engineering team.
- Present SOC performance and compliance reports to internal leadership on a recurring basis; primary point of contact with auditors during audit cycles to resolve compliance findings.
- Liaise with law enforcement on verification and investigation of suspicious IPs.
- Represent the organization as an exhibitor at ANMI Convention and Finbridge Expo.
Apr 2024 — Jan 2026 · Mumbai
Audix Techno Consulting Solutions
Senior Security Operations Analyst — SOC Team Lead
- Led 24x7 SOC operations across Nashik & Mumbai, managing a 24-member team.
- Improved incident resolution efficiency by 30% and cut MTTR by 25% through process redesign.
- Served as Incident Commander for P1/critical incidents — containment, recovery, client communication.
- Implemented external threat intelligence ingestion using External Fabric.
- Primary SOC point of contact for client CISOs and IT leadership during incidents, audits, governance reviews.
- Supported audit and compliance activity aligned with ISO 27001, PCI DSS, and regulatory SOC requirements.
- Coordinated across Firewall, Server, VAPT, GRC, and Dev teams to streamline response and remediation.
- Maintained SOC documentation: SOPs, runbooks, escalation matrices, analyst knowledge bases.
Apr 2022 — Mar 2024 · Mumbai
Audix Techno Consulting Solutions
Cyber Security Analyst
- Monitored SIEM/EDR alerts and performed triage, investigation, and escalation for 24x7 operations.
- Conducted hypothesis-driven threat hunting using SIEM/EDR telemetry to surface stealthy threats.
- Tracked and improved SOC KPIs — MTTD, MTTR, alert volume, SLA adherence.
- Designed, tuned, and optimized SIEM use cases to reduce false positives.
- Conducted Black Box & Grey Box VAPT, application retesting, and remediation validation.
- Designed custom Nessus scan policies and vulnerability reports.
- Led client-facing SOC monthly review meetings; traveled PAN-India for SOC onboarding.