Sagar Patel
Security Engineer | Microsoft 365 Security | Microsoft Defender | SentinelOne | Acronis | KQL | SC-900 | SC-200 | MS-500 | S1QL | GenAI - Copilot Security, Purple AI
Contact Me
Professional Summary
Associate Security Engineer in a fast-paced MSSP environment, managing security operations for four client environments. Part of a 3-member SOC team handling 300–350+ alerts monthly, including bruteforce, password spray, AiTM, MiTM, and phishing attacks using Microsoft Defender, SentinelOne with PurpleAI, and Acronis.
Conduct daily threat hunting using KQL, S1QL, Power Query, and GenAI tools, reducing false positives by 30%. Improved exposure score from 76 to 52 through vulnerability management and coordinated remediation efforts.
Key Achievements
  • 300+ alerts managed monthly
  • 30% reduction in false positives
  • Exposure score: 74 → 52
  • 4 client environments secured
Core Security Expertise
Threat Detection
Monitor and investigate security alerts across multiple platforms including Microsoft Defender, SentinelOne, and Acronis for comprehensive threat coverage.
Threat Hunting
Proactive daily and weekly hunting using KQL, S1QL, Power Query, and GenAI tools to identify misconfigurations and dormant threats.
Incident Response
Handle incident containment, evidence collection, and documentation to strengthen client security posture and ensure rapid response.
Vulnerability Management
Coordinate remediation and patching efforts, successfully improving exposure scores through systematic vulnerability assessment and management.
Attack Types Managed
Brute Force Attacks
Detect and respond to credential stuffing and brute force attempts targeting user accounts across client environments.
Password Spray
Identify and mitigate password spray campaigns attempting to compromise multiple accounts with common passwords.
Phishing & AiTM
Investigate phishing attacks and Adversary-in-the-Middle (AiTM) attacks targeting authentication flows and credentials.
MiTM Attacks
Monitor for Man-in-the-Middle attacks intercepting communications and compromising data integrity.
Technology Stack
Microsoft Defender
Comprehensive endpoint and cloud security monitoring across Microsoft 365 environments.
SentinelOne & PurpleAI
Advanced endpoint protection with AI-powered threat detection and automated response capabilities.
Acronis
Integrated cyber protection combining backup, disaster recovery, and security management.
Query Languages
  • KQL (Kusto Query Language)
  • S1QL (SentinelOne Query Language)
  • Power Query
GenAI Tools
  • Copilot Security Defender
  • PurpleAI
  • AI-assisted threat analysis
Professional Certifications
SC-900
Microsoft Security, Compliance and Identity Fundamentals - Foundation-level understanding of security, compliance, and identity concepts.
MS-500
Microsoft 365 Security Administrator Associate - Expertise in implementing and managing security and compliance solutions.
SC-200
Microsoft Security Operations Analyst Associate - Advanced skills in threat detection, investigation, and response using Microsoft technologies.
SentinelOne Incident Responder
Specialized training in incident response using SentinelOne platform for endpoint security and threat remediation.
Current Role: Stecktra Technologies
Associate Security Engineer | May 2024 - Present
01
Security Monitoring
Conduct alert triage and incident investigation across 4 client environments using multiple security platforms.
02
Threat Hunting
Perform daily and weekly proactive hunting to detect misconfigurations and dormant threats.
03
Vulnerability Management
Coordinate remediation and patching efforts to improve client security posture.
04
Client Communication
Provide daily security recommendations via Zoho Desk and prepare monthly SOC reports.
05
Incident Response
Support containment validation, evidence collection, and documentation for security incidents.
Performance Metrics
300+
Monthly Alerts
Security alerts monitored and investigated each month across client environments.
30%
False Positive Reduction
Improvement in alert accuracy through advanced threat hunting and tuning.
4
Client Environments
Simultaneous security operations management across multiple organizations.
Exposure Score
74 → 52
Significant improvement through coordinated vulnerability remediation and patch management efforts.
Previous Experience
1
Eduquity - Operations
June 2023 - May 2024 | Conducted secure examinations, configured servers and endpoints with Tinywall, worked with Microsoft 365 Defender and Azure Identity Protection, managed SonicWall firewall and network configurations.
2
Corizo - Cyber Security Analyst
March 2023 - May 2023 | Implemented cybersecurity concepts, maintained optimal workflow, and applied security and compliance principles using Azure and M365 tools.
3
Gupta Tuition Classes - Mathematics Educator
July 2018 - August 2021 | Mathematics tutor for class 8-11 science students, handled 30 students in two batches using smart classroom approach.
Get In Touch
Contact Information
Location: Bengaluru, Karnataka, India
Mobile: +917567288879

Languages
  • Gujarati (Native)
  • Hindi (Native)
  • English (Professional)
Made with