Harsimran Sidhu

SECURITY OPERATIONS

Harsimran Sidhu

Security Operations | Incident Response | Threat Intelligence

Security operations analyst with 4+ years of experience across SOC and IT infrastructure. Investigates endpoint, identity, web, email, and network threats; builds detection logic and automation; and turns technical evidence into clear response decisions. Publishes practical SOC playbooks and threat research grounded in real investigation workflows.

01

Experience

Security Operations Center Analyst

Columba System Inc · Remote

  • Investigate endpoint, web, identity, and email-security alerts to validate threats, scope impact, and determine the appropriate response.
  • Build and tune Splunk rules and alerts that support threat detection, triage, and repeatable investigation workflows.
  • Correlate Cortex XDR, WAF, authentication, URL, and email-header evidence to separate malicious activity from false positives.
  • Manage Jira cases from initial triage through documentation and escalation, preserving clear evidence and decision context for IT teams.
  • Automate compliance checks and URL-verification tasks with custom scripts to reduce repetitive analyst work.

Cyber Security Analyst

SecureOps · Remote

  • Investigated and escalated incidents across Microsoft 365 Defender, Splunk, and Microsoft Sentinel within defined service agreements.
  • Wrote Kusto Query Language queries to filter security telemetry, validate alert context, and support incident scoping.
  • Analyzed network traffic with Wireshark and used an AWS sandbox to examine suspicious activity safely.
  • Produced clear investigation updates and coordinated response decisions with distributed technical teams.

Information Technology Specialist

Telecom Metrics Inc · Kingston, Ontario

  • Led security and infrastructure projects supporting server maintenance, reliability, and operational continuity.
  • Implemented high-availability solutions and Python automation for recurring operational tasks.
  • Delivered remote troubleshooting and technical support across infrastructure and end-user systems.

02

Selected security work