
Sudhir Kumar Goswami
Engineering Intern Student

Connect with Sudhir Kumar Goswami to Send Message
Connect
Connect with Sudhir Kumar Goswami to Send Message
ConnectTimeline
About me
CyberSecurity Professional | Detection Engineering | SOAR | Cyber Engineering | Master in CyberSecurity | Securonix Admin Certified | Splunk Admin Certified
Education

S.S College Jehanabad
2006 - 2008Intermediate Science Mathematics and Science Second
High School Tehta
2005 - 2006High School Advanced Mathematics First%2C%20DU%2C%20DRDO.webp)
Defense Institute of Advanced Technology (DIAT), DU, DRDO
2013 - 2015Master of Technology (M. Tech.) Cyber/Computer Forensics and Counterterrorism FirstActivities and Societies: Security, Privacy and Applied Cryptographic Engineering (SPACE), International Association for Cryptologic Research (IACR), Cryptology Research Society of India (CRSI), Central Research Laboratory-BEL Bengaluru, IISc Bengaluru, Research & Development Establishment-DRDO- Pune Institute of Tropical Meteorology (IITM)- Pune, CERT-IN, CDAC Trivendrum, CDAC Pune, CDAC Bengaluru, Cyber Security Researcher, DOD, PCI DSS, InfoSec, ISACA, COBIT, National Cyber Safety and Security Standards Cyber Security Researcher, Ethical Hacking, Business Continuity Plan, Disaster Recovery Plan, Risk Assessment, Network Security, Metasploit, VAPT, Footprinting and Reconnaissance, Scanning Networks, Enumeration, System Hacking, Trojans and Backdoors, Viruses and Worms, Sniffing ,Social Engineering, Denial of Service, Session Hijacking, SQL Injection, Hacking Wireless Networks, Hacking Mobile Platforms, Evading IDS, Firewalls and Honeypots, Buffer Overflows, Cryptography, Penetration… Show more Cyber Security Researcher, Ethical Hacking, Business Continuity Plan, Disaster Recovery Plan, Risk Assessment, Network Security, Metasploit, VAPT, Footprinting and Reconnaissance, Scanning Networks, Enumeration, System Hacking, Trojans and Backdoors, Viruses and Worms, Sniffing ,Social Engineering, Denial of Service, Session Hijacking, SQL Injection, Hacking Wireless Networks, Hacking Mobile Platforms, Evading IDS, Firewalls and Honeypots, Buffer Overflows, Cryptography, Penetration Testing,Risk Management,Security Audits, Nessus Show less

Cochin University of Science and Technology
2010 - 2011Certificate Examination in French French Studies First
Cochin University of Science and Technology
2009 - 2013Bachelor of Technology (B.Tech.) Computer Science & Engineering FirstActivities and Societies: Tech Fest Organiser, Cricket Tournament Organiser, Cricket Team Member, Association of Computer Engineering Students (ACES) Member, Tech Magazine Committee Member, Engineering Student at School of Engineering (SoE, CUSAT)•Developed Android Application named "GPS enabled Smartphone For Traffic Safety System " as Major Project•Developed web application named "ONLINE CINEMA TICKET BOOKING SYSTEM" through ORACLE 11G DB on jsp platform in 6th semester. •Presented seminar on NATIONAL KNOWLEDGE NETWORK at SCHOOL OF ENGINEERING in 7th semester. •Internship program in BLACKBERRY for making an App for BB-10 model conducted by HANGOUT-INDIA at… Show more Engineering Student at School of Engineering (SoE, CUSAT)•Developed Android Application named "GPS enabled Smartphone For Traffic Safety System " as Major Project•Developed web application named "ONLINE CINEMA TICKET BOOKING SYSTEM" through ORACLE 11G DB on jsp platform in 6th semester. •Presented seminar on NATIONAL KNOWLEDGE NETWORK at SCHOOL OF ENGINEERING in 7th semester. •Internship program in BLACKBERRY for making an App for BB-10 model conducted by HANGOUT-INDIA at STARTUP VILLAGE KOCHI. •Completed HACK IT Workshop offered Ankit Fadia organised by Division of information technology, CUSAT in Oct ,2011.•Participated in one day workshop on CYBER SLEUTH by Sunny Veghela workshop at XPLENDOR 2010, organised by SOE CUSAT.• Completed LINUX Workshop offered by the Spoken Tutorial project, IIT Bombay in Sept,2011.• one day workshop on ANDROID Operating System hosted by IPSR solution ltd. and CUSAT.• one day workshop on AEROMODELING AND AIRCRAFT DESIGNING organised by Horizon. Show less
Experience

Bharat Sanchar Nigam Limited
Apr 2011 - May 2011Engineering Intern StudentMobile Communications :- CDMA and GSM2G, Edge InfrastructureNetworking ConceptsBroadband TechnologiesPCM PrinciplesFibre optic TechnologyIntroduction - Digital SwitchesInternet & Email – Visit to NIBGSMIntelligent NetworksLatest trends in CommunicationBroadband Multiplay LabBSNL MuseumTelecom Power PlantLatest BSNL Products
%2C%20DU%2C%20DRDO.webp)
Defense Institute of Advanced Technology (DIAT), DU, DRDO
Jul 2013 - Jun 2015CyberSecurity ResearcherCyberSecurity Researcher, Ethical Hacking,Digital Forensic,Network Security, Information Security,Business Continuity Plan, Disaster Recovery Plan, Risk Assessment, Backdoor OS,Kali Linux OS,Metasploit, VAPT, Footprinting and Reconnaissance tools practical, Scanning Networks,Enumeration, System Hacking, Trojans and Backdoors, Viruses and Worms, Sniffing ,Social Engineering, Denial of Service, Session Hijacking, SQL Injection, Hacking Wireless Networks, Hacking Mobile Platforms, Evading IDS, Firewalls and Honeypots, Buffer Overflows, Cryptography, Penetration Testing,Risk Management,Security Audits, Show less

Jumbo Systems & Solutions Pvt. Ltd
Jun 2015 - Nov 2015Cyber Security ConsultantI was working as Security Consultant for auditing Security framework like PCI DSS, ISMS, HIPAA, and COBIT. I have handled AWS and Non AWS infrastructured clients both auditing PCI DSS.My responsibilities include following.-Scoping -Gap Assessment-Gap Assessment Report Writing-Provide full Remediation-Configuration Check-Evidence Collection-ROC Preparation-Policy Preparation-Procedure Preparation-Forms Preparation-Business DevelopmentTool Knowledge:-• AWS Infrastructure• Ossec• Snort • CryptDB Show less

Tata Consultancy Services
Dec 2015 - Nov 2017CyberSecurity Senior AnalystI was working as L2 level Security Analyst for Security operations Center (SOC) domain with Security Information & Event Management (SIEM) at Cyber Security Practice, TCS in Enterprise Security & Risk Management (ESRM).Tool Knowledge:-• SIEM (Splunk)• Skybox Security• BlueCoat• McAfee ePO• VMS Tripwire 360 nCircle• Juniper Firewall SRX• Cisco IronPort• Cisco Meraki• Juniper IDP• Snow Software: Software Asset Management (SAM)• Security Exception ToolMy Responsibility includes :-• Firewall Approval/Rejection• Manage security incidents and thereby minimizing the Number and Severity of Security Incidents.• Analyze and develop new technologies for minimizing security vulnerabilities and risks• Provide security consulting services.• Routinely assess vulnerabilities and coordinating with security specialist • Routinely monitor and analyze network traffic and system performance.• Responsible for analysis and reporting• Learn about new vulnerabilities and attack strategies employed by attackers.• Monitor firewall, IronPort and IDP logs.• Threat and vulnerability detection.• Handling SOC operations vulnerability assessment tools • Involved in risk analysis of major threats and vulnerabilities detected at client’s network.• Monitoring of Multiple Security Incidents using SIEM tool (Splunk).• Analyzing the offenses for Botnet, P2P activity, Virus threat, Trojan, Malwares, Brute force attack, vulnerability and policy violation activities.• All security events, network transactions and additional contextual information (derived from correlation tests) observed during an attack or violation.• Identify anomalies and possible threats or to review network usage and performance to help meet IT service-level responsibilities.• Finding out the false positive/negative offenses, modifying the rules to ignore the legitimate traffic and reducing the offense count.• Search across logs on different nodes and time periods based on specific criteria. Show less

Accenture Czech Republic
Nov 2017 - nowWorking with Accenture around for 6 years in Cyber Fusion Center (Accenture CFC) in Prague, Czech Republic. Being part of Cyber Defense Team for CyberSecurity engineering role performing SIEM Administrator task. UseCase Creation for CyberOps Team. SOAR Admin Tasks. SIEM platform management end to end. Onboarding of New security tools and devices.CyberUse Cases Creation/Tuning, DataSource Onboarding, Mapping and Parsing, BAS Activity Validation, Purple Activity Validation SIEM Management.Also working on for CyberSecurity UseCase Creation on :IoT Security (Internet of Things)OT Security (Operational Technology)IoMT Security (Internet of Medical Things)ICS Security (Industrial Control System) Show less Associated with Accenture Security around 5 years and now designated at Level 9 as CyberSecurity Engineering & Development Specialist.Currently Part of CyberSecurity Engineering Team handling SIEM Admin Task using Securonix, SNYPR Data Lake, Big Data Platform Hadoop supported by Cloudera for Data source Troubleshooting.Tools and Device Integration, SIEM Platform Handling, UseCase Creation.Newly Data source Onboarding and Continuous tuning of existing datasources.RegEx Writing for new event type and parser creation of various datasources.Define & Building SIEM custom use cases, content development for various data source.Finetuning of the existing Use cases to reduce false positive and noise. Parsing, mapping and remapping of the attributes. Checking Health check of Hadoop HDFS nodes for memory, cpu, disk utilization for smooth functioning. DR Implementation for Various datasources.Playbook Creation using SOAR.Playbook monitoring and troubleshooting for smooth functioning.RIN (Remote Ingestion Node) and syslog servers monitoring and implementing configuration for datasources.Configuring and updating the SYSLOG server for receiving the logs and forwarding the logs to various SOLR cell using SYSLOG NG config files.Creating Threat Models.Working within current change management processes to apply patches and provide first-line support for supported security tools.Feed intelligence and indicators of compromise to security incident management during P1 and P2 incidents to support the incident management process via triage on security events.Produced actionable intelligence for colleagues and business areas in the form of threat advisories, briefings, a threat attribution database and tactical data feeds.Provided technical governance, oversight and direction for the overall security service, solution design and implementation compatible with the target state operational security architecture.SNYPR Datalake, FortiSOAR, Cloudera, Apache Spark jobs Show less Currently Part of CyberSecurity Engineering Team handling Admin Task using Securonix, SNYPR Data Lake, Big Data Platform Hadoop supported by Cloudera and various data sources for Data source Troubleshooting, Data source Onboarding, RegEx Writing, Define & Building SIEM custom use cases, content development for various data source, Finetuning of the existing Use cases to reduce false positive and noise. Parsing, mapping and remapping of the attributes. Checking Health check of Hadoop HDFS nodes for memory, cpu, disk utilization for smooth functioning. Cofniguring and updating the SYSLOG server for receiving the logs and forwarding the logs to various SOLR cell using SYSLOG NG config files.Creating Threat Models.Using following Hadoop Component:HDFSSOLRSPARK (12 Jobs)ZookeeperHBaseYARNHIVEIMPALAKAFKASentryHueOozie Show less I was part of Cyber L2 Team for Securonix SIEM Team handling below tasks using SNYPR tool with multiple native tools for investigation.- Fine tuning suggestion- Working on Top violators, violations and multiple Threat Models to capture high severity violators.- handling Client call and expectation- Weekly, monthly Report Preparation- Handling multiple High priority P1 and P2 issues- Datasource health check report preparation- Dashboard creation in SNYPR- KT to Team and junior resource- Brown Bag session to team as in when required for new cyber threats.- Preparing Baseline Report for Clients.- Directly Investigating with the users for Audit Frameworks like GDPR, HIPAA, PCI DSS etc and taking it to resolution.Also Handled Splunk Admin Task in previous project in Accenture for Handling Splunk components like Search Head, Deployment server, Forwarders, License Master, Indexers etc for SIEM functioning, Define & Building SIEM custom use cases, Full platform support to Splunk v6.4.2 solutions, Splunk health monitoring and maintaining.Managed Splunk configuration files like indexes.conf, inputs.conf, outputs.conf, props.conf, savedsearches.conf etc.Experience with monitoring and operating SIEM, EDR and IDS/IPS solutions alongside other critical monitoring toolsets.Experience with Incident Response methodology in investigations, and the groups behind targeted attacks and tactics, techniques, and procedures (TTPs).Monitoring security devices for server and workstation in various sites across globe and Routinely assess vulnerabilities and coordinating with security specialist. Routinely monitor and analyze network traffic and system performance. Also handling below tools.--------------SplunkSecuronix SNYPRFireEye HX & NXTaniumCybereason (EDR)AirwatchInfoblox IPAMAlcatel-Lucent VitalQIP DNS/DHCP IPAMPalo Alto Network (PAN) FirewallPAN MineMeldiDefense® Security IntelligenceAmazon Web Services (AWS)RSA Archer for Ticket ManagementService Now Show less
CyberSecurity Engineering Associate Manager
Dec 2023 - nowCyberSecurity Engineering & Development Specialist
Dec 2022 - Nov 2023CyberSecurity Engineering & Development Lead
Dec 2020 - Dec 2022CyberSecurity Senior Development Engineer
Apr 2019 - Dec 2020CyberSecurity Delivery Senior Analyst
Nov 2017 - Aug 2019
Licenses & Certifications

High Performance(HPC), Grid and Cloud Computing (HGCC) Training
C- DAC PuneSept 2014
SailPoint Training
SailPointJan 2016
Cyber Security and Cyber Forensics Training
CDAC BangaloreApr 2014
Digital Forensic Training
CDAC - ThiruvananthapuramMar 2015
PSE: Platform Associate 7.0 (Palo Alto Networks-accredited System Engineer (PSE) )
Palo Alto NetworksFeb 2017
Splunk Certified User 6.x
SplunkNov 2017
Splunk Certified Power User 6.x
SplunkJan 2018
Accredited Configuration Engineer (ACE) - PAN-OS 7.0 Version
Palo Alto NetworksFeb 2017
Assurance / Digital : Assurance for the Internet of Things (IoT)
Tata Consultancy ServicesJan 2017
Skybox Security Training
Skybox SecurityJun 2016
Honors & Awards
- Awarded to Sudhir Kumar GoswamiStar Performer - Apr 2020
- Awarded to Sudhir Kumar GoswamiCool Collaborator - Jun 2019
- Awarded to Sudhir Kumar GoswamiInfoSecurity Fest Winner Technology Business Unit, Tata Consultancy Services Mar 2017
Volunteer Experience
Conference Organizer
Issued by SPACE International Conference at DIAT on Oct 2014
Associated with Sudhir Kumar GoswamiTree Planter
Issued by Self4Society on Jul 2019
Associated with Sudhir Kumar GoswamiCorporate Social Responsibility
Issued by Accenture on Nov 2017
Associated with Sudhir Kumar Goswami
Languages
- enEnglish
- frFrench
- hiHindi
Recommendations

Saurav b.
Application EngineerAustralia
Anudeep marlapalli
Full Stack and Data Science Trainer at ExcelR and Full stack Academy with expertise in MERN Stack an...Hyderabad, Telangana, India
Caity hoover, m.ed., acc
ICF-Credentialed Coach + Leadership Trainer Helping visionary leaders with Mindset Mastery to Thrive...Houston, Texas, United States
Lawal abdulaziz
EX META | MARKETING MANAGER | DIGITAL MARKETINGBaltimore, Maryland, United States
Panneerselvam kolandaivel
Information Security ManagerBengaluru, Karnataka, India
Sandy ye
RN, MSN, FNP-BCNew York City Metropolitan Area
Shreyas narayanan, frm®
Associate at JPMorgan Chase & Co.Bengaluru, Karnataka, India
Razvan fotia
Digital marketing maverick, certified by Google, Meta, and HubSpot. I share what I know and learn.Bucharest, Romania
Caio gonçalves
Process analyst | Operations Kad | Green beltSão Paulo, São Paulo, Brazil
Myrna heunis
Group Legal Manager (Lesaka Group)Cape Town, Western Cape, South Africa
John emmanuel dela cruz
Aeronautical EngineerBaliuag, Central Luzon, Philippines
M. cantoli
HR ConsultingArgentina
Danielle vasconcellos habib
Legal Counsel na @Neon | Litigation | Legal Marketing | Banking | InovationSão Paulo, São Paulo, Brazil
Fadi alam aldeen al hasbani
Manager at Net Marketingمسقط عمان
Oran croft
Environmental Engineer, Hazardous Waste Management and SPCC RegulationsProvo, Utah, United States
Krissy tripp
Senior Director, Decision ScienceKansas City, Missouri, United States
Hana talitha argani
Product Development Manager at PT Trimegah Asset ManagementJakarta, Jakarta, Indonesia
Rebecca rogers, ph.d., msw, m.ed.
Director| Faculty Member | Board Member| Workforce Development | Licensed Social WorkerLas Vegas, Nevada, United States
Ankita satpathy
Chief of Staff - Founder's Office | SAP Sales & Marketing | SAP Pre-Sales | Project Coordination | ...Bengaluru, Karnataka, India
Reem aroj
Campaign Specialist | Programmatic Direct | Digital MarketerBengaluru, Karnataka, India
...