Cybersecurity Analyst · Mid-level · ~5 yrs

Fatima Qureshi

Senior Cybersecurity Analyst / SOC Tier 2

Professional summary

Cybersecurity analyst with 5 years in 24x7 SOC and threat-detection teams across BFSI and SaaS. Owns the full incident-response lifecycle — detection through containment, eradication and lessons-learned — and tunes SIEM content (Splunk, Microsoft Sentinel) that materially cuts dwell time. Runs vulnerability-management programs, supports ISO 27001 audits, and mentors Tier 1 analysts on triage quality and ATT&CK-driven hunting.

41%

Faster mean time to detect

12k

Endpoints defended 24x7

300+

Incidents resolved / year

Skills

Detection & response

SIEM (Splunk, Microsoft Sentinel)EDR (CrowdStrike, Defender)Incident responseThreat huntingMITRE ATT&CKSOAR playbooks

Vulnerability & offensive

Vulnerability assessmentPenetration testingNessus / QualysBurp SuitePatch & risk prioritization (CVSS)

Network & cloud

Firewalls (Palo Alto, Fortinet)IDS/IPSAWS security (GuardDuty, IAM)DNS/HTTP analysisZeek

Governance & compliance

ISO 27001NIST CSFPCI-DSSRisk assessmentSecurity awarenessAudit support

Work experience

Cybersecurity Analyst (SOC Tier 2) · Aegis FinServ

Apr 2022Present

Hyderabad

  • Lead incident response for a 24x7 SOC protecting 12,000 endpoints; reduced mean time to detect 41% (38 min → 22 min) by re-engineering Splunk correlation searches.
  • Resolved 300+ security incidents/year including 3 confirmed intrusions, containing the worst within 35 minutes and limiting blast radius to a single segment.
  • Built 26 SOAR playbooks in Splunk Phantom that auto-triage phishing and isolate hosts, saving the team ~18 analyst-hours/week.
  • Ran the vulnerability-management cycle across 900+ assets with Qualys, driving the critical-finding backlog down 73% in two quarters.
  • Mentored 4 Tier 1 analysts and authored the ATT&CK-aligned hunt playbook now used as the team standard.

Security Analyst (SOC Tier 1/2) · Cobalt Cloud Systems

Jul 2020Mar 2022

Bengaluru

  • Monitored Microsoft Sentinel and CrowdStrike alerts for a SaaS platform, tuning rules that cut false positives 35% and lifted true-positive yield.
  • Conducted quarterly internal penetration tests and vulnerability assessments, reporting 120+ findings and verifying fixes in re-tests.
  • Hardened firewall and IAM policies during an ISO 27001 certification effort, closing 19 audit non-conformities ahead of the assessor visit.

Featured projects

−41% MTTD
DwellCut — detection engineering

Internal initiative to systematically lower attacker dwell time across the SOC.

  • Mapped detection coverage to MITRE ATT&CK and closed 28 technique gaps, raising coverage from 61% to 88%.
SIEMThreat detectionMITRE ATT&CK

Education

B.E. Computer Science & Engineering

2020

Osmania University, Hyderabad

First Class with Distinction

Certifications

GIAC Certified Incident Handler (GCIH)

GIAC · 2023

CompTIA CySA+

CompTIA · 2022

ISO/IEC 27001 Lead Implementer

PECB · 2023

See the work in 3D

Explore Fatima's interactive WebGL portfolio — projects, skills and a way to get in touch.