Back
Tarunteja Desireddy
Azure Security Engineer · Doha, Qatar
My work splits two ways. I engineer the platform — Microsoft Sentinel deployed as infrastructure-as-code, new log sources and data connectors brought online, external data and threat intelligence integrated through APIs. And I operate it — KQL analytics rules and hypothesis-driven hunt packages authored and tuned on top, SOAR playbooks built to act on them, and alert triage, root-cause analysis, and coordination when an incident escalates against an SLA.
Experience
SOC Engineer — Mannai Technologies — Microsoft HubJan 2024 – Present · Doha, Qatar
- Deploy and configure Microsoft Sentinel workspaces; onboard log sources and data connectors as new coverage comes online
- Author and tune KQL analytics rules mapped to MITRE ATT&CK; integrate external threat-intelligence feeds through Sentinel's ingestion APIs
- Run proactive, hypothesis-driven threat hunting in KQL — hunt packages mapped across the MITRE ATT&CK matrix
- Build SOAR: Logic App playbooks, Sentinel automation rules, and Azure Automation runbooks for enrichment, notification, and response — authenticated with Key Vault-backed managed identity
- Operate multi-SIEM across Microsoft Sentinel, Google SecOps (Chronicle), and LogRhythm
- Investigate across Azure workloads and identity with Microsoft Defender for Cloud, Entra ID, Azure Monitor, and Log Analytics
- Incident response and escalation: alert triage, root-cause analysis, SLA tracking, coordination on high-severity incidents, and Sentinel workbooks for operational reporting
SOC Analyst — MGS TechnologyOct 2022 – Jan 2024 · Remote
- Monitored SIEM alert queues, carried out initial triage, and separated true positives from false positives
- Escalated confirmed incidents to L2 with investigation notes and supporting evidence
- Ingested IOCs from threat-intel feeds and vendor advisories and matched them against environment telemetry
- Produced shift-handover, weekly alert-trend, and monthly operational reports feeding tuning recommendations back to senior analysts
- Maintained investigation records and runbook documentation; followed escalation paths and tracked ticket SLAs
Selected projects
Detection engineering portfolio — 60 ATT&CK-mapped KQL analytics rules, Bicep-deployed Sentinel, and secretless SOAR — public on GitHub.
Detection & response engineering — The standing practice — rules, hunts, and automation on one ATT&CK model.
Skills
SIEM & Platform EngineeringMicrosoft Sentinel · Google SecOps (Chronicle) · LogRhythm · Sentinel deployment & configuration · Workspace config as code · Bicep / ARM templates · Log Analytics & Azure Monitor · Sentinel workbooks
Data Onboarding & IntegrationLog source onboarding · Data connector configuration · Data Collection Rules · External data & API integration · Threat-intel pipeline (API-driven) · Microsoft Graph API automation
Detection EngineeringKQL · Analytics rule authoring · Detection tuning for signal · 60 published ATT&CK-mapped rules · MITRE ATT&CK mapping
Threat Hunting & Threat IntelligenceHypothesis-driven threat hunting · KQL hunting · ATT&CK-mapped hunt packages · Cyber threat intelligence · IOC enrichment · OSINT collection
Automation, SOAR & Incident ResponseAzure Logic Apps playbooks · Sentinel automation rules · Azure Automation runbooks · Alert enrichment & notification · Key Vault-backed managed identity · Alert triage & escalation · Root-cause analysis · SLA tracking
Identity, Access & Cloud SecurityMicrosoft Entra ID · Identity activity investigation · Azure RBAC scope & inheritance · Least-privilege automation identities · Microsoft Defender for Cloud · Security posture review · Azure workload investigation
Certifications
- Microsoft Certified: Azure Security Engineer AssociateMicrosoft · 2023
- Microsoft Certified: Security Operations Analyst AssociateMicrosoft · 2023
- Google Cloud Certified: Professional Security Operations EngineerGoogle Cloud · 2026
- Cisco Certified: Ethical HackerCisco · 2025
- LogRhythm Security Analyst (LRSA)Exabeam · 2025
- Introduction to Threat HuntingSecurity Blue Team · 2023
- Introduction to Network AnalysisSecurity Blue Team · 2023
- Introduction to OSINTSecurity Blue Team · 2025
Education
Sri Venkateswara University — India
desireddy.com — this page has the current detail; export to PDF from your browser if you need a file.