SECURITY OPERATIONS
Harsimran Sidhu
Security Operations | Incident Response | Threat Intelligence
Security operations analyst with 4+ years of experience across SOC and IT infrastructure. Investigates endpoint, identity, web, email, and network threats; builds detection logic and automation; and turns technical evidence into clear response decisions. Publishes practical SOC playbooks and threat research grounded in real investigation workflows.
01
Experience
Security Operations Center Analyst
Columba System Inc · Remote
- Investigate endpoint, web, identity, and email-security alerts to validate threats, scope impact, and determine the appropriate response.
- Build and tune Splunk rules and alerts that support threat detection, triage, and repeatable investigation workflows.
- Correlate Cortex XDR, WAF, authentication, URL, and email-header evidence to separate malicious activity from false positives.
- Manage Jira cases from initial triage through documentation and escalation, preserving clear evidence and decision context for IT teams.
- Automate compliance checks and URL-verification tasks with custom scripts to reduce repetitive analyst work.
Cyber Security Analyst
SecureOps · Remote
- Investigated and escalated incidents across Microsoft 365 Defender, Splunk, and Microsoft Sentinel within defined service agreements.
- Wrote Kusto Query Language queries to filter security telemetry, validate alert context, and support incident scoping.
- Analyzed network traffic with Wireshark and used an AWS sandbox to examine suspicious activity safely.
- Produced clear investigation updates and coordinated response decisions with distributed technical teams.
Information Technology Specialist
Telecom Metrics Inc · Kingston, Ontario
- Led security and infrastructure projects supporting server maintenance, reliability, and operational continuity.
- Implemented high-availability solutions and Python automation for recurring operational tasks.
- Delivered remote troubleshooting and technical support across infrastructure and end-user systems.
02
Selected security work
Web and Identity Incident Response
Published hands-on playbooks for WordPress compromise and WAF login attacks, covering triage, evidence preservation, log analysis, scoping, containment, and hardening.
Read the case file →Threat Research
Analyzed Qilin ransomware, the XZ supply-chain backdoor, and Cortex XDR abuse patterns with attack timelines and defensive recommendations.
Read the case file →Security Engineering and Automation
Built Python website monitoring, Docker-based network protection, and GitHub/Azure CI/CD projects documented for other practitioners.
Read the case file →