SS
Shubham.SCybersecurity Expert

ยฉ 2024 CyberPortfolio

Online

Professional Experience

My journey through cybersecurity, from foundational IT support to leading enterprise incident response teams.

โšกExperience Timeline

๐Ÿ”

Deloitte

Jan 2023 โ€“ Present

Current
๐Ÿงช

Sophos

Nov 2020 โ€“ Jan 2023

๐Ÿ’ป

eClinicalWorks

Jul 2018 โ€“ Nov 2020

๐Ÿ”

Deputy Manager โ€“ CSIRT

Deloitte

Jan 2023 โ€“ Presentโ€ขMumbai, India
|

๐Ÿ“ŠKey Metrics

0+
Incidents Handled
0
Team Size
0%
Improvement
0
Tools Mastered

๐Ÿ†Key Achievements

1
โšก

Enterprise Incident Response Leadership

High ImpactAchievement #1
5/5

Operated in a high-pressure CSIRT environment, managing enterprise-scale incident response for ransomware outbreaks, cobalt strike intrusions, command-and-control (C2) callbacks, and suspicious persistence mechanisms.

High Priority
Strategic Impact
2
๐Ÿ”

Advanced Forensic Analysis

High ImpactAchievement #2
5/5

Performed end-to-end forensic investigations, acquiring memory dumps, analyzing Master File Table (MFT), parsing shell artifacts, and extracting volatile indicators to determine root cause and threat actor behavior.

High Priority
Strategic Impact
3
๐Ÿ’ป

Detection Engineering Excellence

High ImpactAchievement #3
5/5

Led reverse engineering of malware payloads (obfuscated DLLs, PE files, and encrypted scripts) using disassemblers and emulation tools, enabling early-stage detection of custom malware and LOLBins abuse.

High Priority
Strategic Impact
4
๐Ÿ›ก๏ธ

Threat Detection & Containment

High ImpactAchievement #4
5/5

Built and refined detection rules (EDR + SIEM), optimizing telemetry logic to detect rare behaviors like token impersonation, parent-child process anomalies, and native API misuse.

High Priority
Strategic Impact
5
๐Ÿ”„

SOAR & Automation

High ImpactAchievement #5
5/5

Automated containment and recovery workflows using SOAR (XSOAR Cortex), reducing time-to-response (MTTR) for critical alerts across the enterprise.

High Priority
Strategic Impact
6
๐Ÿ“š

Playbook Development

High ImpactAchievement #6
5/5

Drafted enterprise-wide SOPs and playbooks for incidents involving web shell exploitation, lateral movement, credential theft, and cloud-native attacks (Azure/AWS).

High Priority
Strategic Impact
7
๐Ÿ‘ฅ

Team Development & Mentorship

High ImpactAchievement #7
5/5

Mentored L1 analysts and junior responders through ransomware simulations, real-time triage exercises, and forensic case studies, driving a 92% improvement in detection precision.

High Priority
Strategic Impact
8
๐Ÿค–

AI & ML Integration

High ImpactAchievement #8
5/5

Integrated OpenAI APIs to develop early-stage threat narrative classification models, automating contextual alert analysis and tagging within SOC workflows.

High Priority
Strategic Impact
9
๐Ÿ”‘

Decryption Research

High ImpactAchievement #9
5/5

Actively contributed to ransomware decryption research, integrating YARA-based scanning logic for novel strains and deploying resilient backup validation methods.

High Priority
Strategic Impact
10
๐ŸŽฏ

Advanced Detection Engineering

High ImpactAchievement #10
5/5

Helped in tuning the detection logic for ransomware and other threats and created a custom detection logic on Splunk and MDE using KQL

High Priority
Strategic Impact
11
๐ŸŒ

Threat Hunting & Detection

Medium ImpactAchievement #11
3/5

Worked closely with iBoss, Zscaler, and Cisco Stealthwatch telemetry for east-west traffic inspection, DLP monitoring, and anomaly detection.

High Priority
Strategic Impact
11

Total Achievements

11 major accomplishments with significant business impact

11
Achievements

๐Ÿ› ๏ธSkills & Technologies

Incident ResponseMemory ForensicsRansomware AnalysisMITRE ATT&CKSOAREDR/SIEMMalware Reverse EngineeringThreat HuntingDetection EngineeringCSIRT Leadership