ChandreshKumarKarn. — Cybersecurity Engineer & SOC Leader
SOC Operations · Detection Engineering · SIEM/XDR/SOAR · Incident Response · Security Automation
Cybersecurity engineer with 4+ years across SOC operations, SIEM engineering and detection engineering for enterprise clients — log source onboarding and SIEM integration, correlation rule and use case development, detection tuning, incident response and threat investigation.

Synthetic telemetry generated for portfolio demonstration. No customer or production data is displayed.
The engineer behind SecureWithCK.
Cybersecurity engineer with 4+ years across SOC operations, SIEM engineering and detection engineering for enterprise clients — incident response, threat investigation and security automation, with VAPT, GRC and data privacy as supporting strengths.
Cybersecurity engineer with 4+ years of experience across SOC operations, SIEM engineering and detection engineering for enterprise clients in the US, UK and Singapore.
Hands-on with end-to-end log source onboarding and SIEM integration, log parsing and normalization, correlation rule and use case development, detection tuning, incident response, forensic and root cause analysis, and MITRE ATT&CK-aligned investigation across IBM QRadar, Microsoft Sentinel, Splunk, Darktrace and Cortex XSIAM/XDR/XSOAR.
Automation and scripting in Python, PowerShell and Bash, plus independent VAPT engagements, GRC and data privacy advisory, and technical-to-executive stakeholder communication.
- 01End-to-end log source onboarding and SIEM integration
- 02Correlation rule and use case development
- 03Detection tuning and alert investigation
- 04Incident triage, response and root cause analysis
- 05Post-integration and correlation rule validation
- 06Vulnerability assessment lifecycle and remediation follow-up
- 07Security posture and SLA reporting
- 08Junior analyst mentoring and security awareness training
SOC Operations
Enterprise security monitoring, incident triage and response across US, UK and Singapore client environments.
Detection Engineering
Use case development, correlation rules and detection tuning mapped to MITRE ATT&CK.
SIEM / XDR / SOAR
IBM QRadar, Microsoft Sentinel, Splunk, Darktrace and Cortex XSIAM / XDR / XSOAR.
Log Source Integration
End-to-end onboarding via Syslog, API and agents — parsing, normalization and event categorization.
Incident Response
Triage, forensic analysis, root cause analysis and remediation strategy for escalated incidents.
Security Automation
Automation and tooling with Cortex XSOAR plus Python, PowerShell and Bash.
VAPT & GRC
Independent VAPT engagements, CVSS-aligned risk classification, GRC and data privacy advisory.
Stakeholder Communication
Technical reporting and executive briefings that translate security findings for the business.
Evidence, not estimates.
Capability areas backed by hands-on enterprise security operations work. Figures are shown only where they can be stated as fact.
Quantified career metrics are deliberately withheld until independently verifiable. Capability statements above describe work performed, not estimated volumes.
Experience timeline.
SOC operations, SIEM integration, detection engineering and incident response for enterprise clients across the US, UK and Singapore — plus independent VAPT, GRC and data privacy consulting.
SOC Implementation Lead — Multiple Clients
Leading end-to-end log source onboarding and SIEM integration across servers, network devices and security tools, through to validated production monitoring readiness.
- Own end-to-end log source onboarding and SIEM integration for enterprise clients
- Integrate servers, network devices and security tools via Syslog, API and agent-based collection
- Build log parsing, normalization and event categorization for onboarded sources
- Troubleshoot ingestion failures and EPS fluctuations across collection paths
- Run post-integration validation and correlation rule validation before handover
- Confirm production monitoring readiness with SOC monitoring teams
- Coordinate with infrastructure, network and application teams during onboarding
- Maintain integration documentation to support operational continuity
SOC Engineer — US & SG Clients
Enterprise monitoring, incident triage and response, forensic and root cause analysis, vulnerability assessment lifecycle and security posture reporting.
- Delivered enterprise security monitoring, incident triage and incident response
- Performed forensic analysis and root cause analysis, then defined remediation strategy
- Ran the vulnerability assessment lifecycle from discovery through remediation follow-up
- Produced weekly and monthly security posture and SLA reporting for stakeholders
- Worked across firewalls, IDS/IPS, DLP and security architecture reviews
- Delivered security awareness training for client teams
- Mentored junior analysts on triage quality and escalation discipline
SOC Analyst — US & UK Clients (Offsite)
Monitoring, alert triage and security event analysis with incident investigation and escalation across enterprise client environments.
- Monitored enterprise environments and triaged security alerts end-to-end
- Performed security event analysis, incident investigation and escalation
- Operated IBM QRadar, Darktrace and ServiceNow for detection and case handling
- Supported forensic analysis and root cause analysis on escalated incidents
- Contributed to vulnerability assessment activity and remediation follow-up
- Reviewed firewall, IDS/IPS, DLP and security architecture configurations
- Authored security documentation, incident response plans and risk assessments
Independent Security Consultant — VAPT, GRC & Data Privacy
Independent VAPT engagements alongside GRC and data privacy advisory, delivered with technical reporting and executive briefing.
- Delivered independent VAPT engagements; latest assessment covered 3 network segments and 112 assets
- Performed network and host vulnerability discovery with CVSS-aligned risk classification
- Identified Critical findings including remote code execution exposure
- Provided remediation guidance, a technical report, a remediation guide and an executive briefing
- Added MITRE ATT&CK context and highlighted detection and monitoring blind spots
- Advised on GRC alignment across ISO 27001, SOC 2, NIST CSF and PCI-DSS
- Advised on data privacy under GDPR and India's DPDP Act, assessing controls and data-handling practices
Core expertise.
Technologies and capabilities grouped by discipline — SOC, detection engineering and SIEM/XDR/SOAR first, no self-assigned proficiency scores.
Built, not just operated.
Security tooling and platforms engineered hands-on — led by a local-first endpoint security / XDR build.
Secure-One
An independent, Windows-focused endpoint security and XDR project — security telemetry, detection engineering, behavioral NGAV concepts, threat intelligence correlation and active response — built to understand how detection and response products work internally, not just how to operate them.
- 01Endpoint Telemetry
- 02Unified Event Pipeline
- 03Detection Engine
- 04Behavioral NGAV
- 05Threat Intelligence
- 06Correlation
- 07Active Response
- 08Host Firewall
- 09SOC Workflows
Bulk IP/URL/Domain Reputation Checker
Python-based threat-intelligence reputation utility for batch IP, URL and domain lookups supporting SOC triage.
LogSense
Security log analysis utility that parses security event data and surfaces anomalies to speed investigation and detection workflows.
Domain Security Checker
Automated domain-security posture scanner covering DNS, SSL/TLS and related configuration checks.
Threat Intelligence Platform
Centralized platform concept for aggregating and correlating threat-intelligence feeds to support proactive detection and use case development.
Case files.
Selected technical investigations, engineering challenges and SOC improvements presented without exposing customer-confidential information.
All case studies are sanitized. Customer names, infrastructure identifiers, IP addresses, internal configurations and confidential information have been removed or generalized.
SOC monitoring, demonstrated.
A simulated security operations view built to demonstrate detection engineering, ATT&CK coverage mapping and triage workflow — using synthetic data only.
SIMULATED ENVIRONMENT · Synthetic telemetry generated for portfolio demonstration. No customer or production data is displayed.
GRC & data privacy.
An extension of hands-on cybersecurity engineering — not the primary career identity. No compliance scores or maturity percentages are claimed.
GRC Advisory
Controls and policy assessment against ISO 27001, SOC 2, NIST CSF and PCI-DSS, carried out alongside hands-on security operations work.
Data Privacy
Data privacy advisory under GDPR and India's DPDP Act — reviewing data-handling practices and the controls that support them.
Risk Assessment
Risk assessment and CVSS-aligned classification of findings, with remediation guidance mapped to business impact.
Executive Reporting
Technical reports, remediation guides and executive briefings that translate security findings for non-technical stakeholders.
Certification, training & education.
Only credentials that are actually held. Training and courses are labelled as such, never presented as certifications.
- Microsoft Azure CertificationTCS / Microsoft
- Software Security AssuranceTCS HiTech
- Unix/Linux BasicsRedHat
- Data Science SpecializationUniversity of Michigan (Coursera)
- Applied Machine Learning in PythonUniversity of Michigan (Coursera)
- R ProgrammingJohns Hopkins University (Coursera)
- Introduction to Machine LearningDuke University (Coursera)
- Business CommunicationTCS
- Machine First and Intelligent Business ProcessesTCS
Achievements & recognition.
Verified recognition only — awards, speaking invitations and academic honours as stated on the resume.
Most Influential Data Analytics Professional – Asia Pacific
Invited guest speaker and panelist for contributions to data analytics.
Golden Guru 2023
Recognized for voluntarily training unallocated TCS associates in Python and Machine Learning.
Xperience Learner
Completed advanced technical courses and ranked among top performers company-wide.
Sage Career Day 2025
Recognized as Best Student of the 2018–2022 term for academic and cybersecurity performance.
1st Rank — Research Paper Writing Competition
Paper: Classification of Shoppers' Intention.
Signal, not Noise
Cybersecurity education and field notes from SOC operations. Published items link to the source; everything else is marked upcoming.
#30DaysSOCSeries
PUBLISHED ON LINKEDINA practical cybersecurity series covering SOC operations, alert triage, security monitoring, cybersecurity labs, career development, and defensive security concepts.
Practical lessons and perspectives on SOC operations, defensive security, hands-on learning, and building a career in cybersecurity.
SOC Certifications
Building a Cybersecurity Lab for SOC Practice
Making a SOC Resume Stand Out
Engineering detections that don't drown analysts
How I score detection logic for fidelity, context and analyst actionability before it goes live in production.
QRadar → Cortex XSIAM: migrating without coverage gaps
Detection parity, log source onboarding order and cutover sequencing — notes from real platform migration work.
Where automation actually helps a SOC
Practical SOAR and enrichment patterns that reduce analyst toil, and the ones that only add moving parts.
Open to opportunities.
Looking for roles centred on SOC engineering, detection engineering, SIEM/XDR/SOAR, incident response and security automation — with VAPT, GRC and data privacy as secondary areas of fit.
Let’s talk about the role.
Recruiters, hiring managers and security leaders — reach out about cybersecurity engineering, detection engineering, SIEM/XDR or SOC leadership opportunities. I respond to every genuine enquiry.