Sadashiv Pole
SOC & Cybersecurity Engineering

Security Operations Engineer with hands-on 24/7 SOC experience — transforming cybersecurity operations through AI-powered workflows, real-time threat detection, and proactive incident response. Specialising in SIEM engineering across Splunk, FortiSIEM, Microsoft Sentinel, Wazuh, and QRadar — including parser development, detection rule design, and security automation.

🟢 Open to SOC roles and security automation projects
Top 1% TryHackMe531+ Day Streak52 Badges345+ LabsTop 6% BTLOSC-200 CertifiedSIEM TOOLSAI automation
100+
Alerts Triage Daily
4+
SIEM Platforms
345+
THM Labs Completed
24/7
SOC Environment
View Projects
About Me

I am a Security Operations Engineer with a proven track record in 24/7 SOC environments, threat detection, and security automation. My hands-on approach — from building custom FortiSIEM parsers to deploying AI-powered phishing detection systems — is grounded in real-world incident response experience within a banking sector SOC.

I hold a Microsoft SC-200 certification and rank in the Top 1% globally on TryHackMe, where I maintain a 531+ day learning streak. My non-traditional academic background (B.Com, Kakatiya University) has only sharpened my drive: every certification, lab, and project is earned through genuine effort and practical application.

I write about cybersecurity on Medium and actively contribute to the SOC community through technical blog posts, CTF participation, and open-source automation tools.

Experience
TechOwl Infosec Pvt. Ltd — Banking Client

SOC L1 — Cyber Security Engineer | Dec 2025 – Jun 2026 | Surat, India | Full-Time

Core Responsibilities
  • Monitored and triaged 100+ security alerts daily in a 24×7 SOC using FortiSIEM and Splunk
  • Investigated phishing, brute-force, unauthorized access, and account compromise via Windows/Linux/Firewall logs
  • Developed Regex-based parsers to onboard log sources into FortiSIEM
  • Created and optimized SIEM correlation rules to reduce false positives
Key Achievements
  • Automated IOC enrichment via VirusTotal & AbuseIPDB APIs — reducing manual investigation effort
  • Conducted endpoint threat investigations using Microsoft Defender for Endpoint (MDE)
  • Monitored endpoints via CrowdStrike Falcon and SentinelOne
  • Applied MITRE ATT&CK Framework to map adversary TTPs
  • Performed vulnerability assessments using Nessus, Nmap, Burp Suite, Wireshark, and Kali Linux
Experience
TryHackMe — Self-Directed Learning

SOC Analyst & Security Engineering Learner | Aug 2023 – Present | Remote | Top 1% Globally

345+ Labs Completed

Top 1% global ranking with 52 badges and a 531+ day learning streak.

Learning Paths

Security Engineer, SOC Level 1, Web Fundamentals, Intro to Cyber Security, Pre-Security, Advent of Cyber 2024 & 2025.

Practical Skills

Security Monitoring, Threat Detection, Incident Response, SIEM Operations, Active Directory, Windows & Linux Security, Network Security.

Featured Project
AI-Powered Phishing Detection System

Autonomous phishing detection agent built with n8n and Google Gemini AI. Monitors inbound emails via IMAP, runs AI-driven analysis, and delivers real-time SOC alerts — reducing analyst workload while handling thousands of emails daily.

95%
Detection Accuracy
<20s
Alert Speed
47×
Faster Analysis
Technologies

n8n · Google Gemini 2.5 · JavaScript · IMAP · REST APIs

How It Works

Monitors inbound emails via IMAP, runs AI-driven analysis using Google Gemini 2.5, and delivers real-time SOC alerts — reducing analyst workload while handling thousands of emails daily.

Projects
IOC Enrichment & Phishing URL Investigation
Project 02: IOC Enrichment Automation

Automated ingestion of suspicious IPs and file hashes from SIEM alerts. Enriched in real-time via VirusTotal and AbuseIPDB APIs, with critical threats routed instantly to Slack — eliminating manual lookups during triage.

5s Response Time100% Auto-Scored IOCs

n8n · VirusTotal API · AbuseIPDB API · Slack · REST APIs

Project 03: Real-World Phishing URL Investigation

End-to-end OSINT investigation of live phishing domains. Extracted 10+ IOCs, enriched across four intelligence sources, and authored professional SOC-style incident report with full takedown support documentation.

10+ IOCs Extracted4 Threat Intel Sources

OSINT · VirusTotal · URLScan.io · Hybrid Analysis · AbuseIPDB


FortiSIEM Custom Parser Development

Developed Regex-based parsers in FortiSIEM to normalise raw syslog data from multiple network sources — enabling structured event ingestion, accurate correlation, and improved visibility across the SOC monitoring stack.

Multiple Log Sources

Onboarded diverse network sources into FortiSIEM for centralized monitoring.

Reduced False Positives

Improved alert fidelity and detection accuracy for Tier 1 analysts.

Detection Engineering

Structured event ingestion enabling accurate correlation across the SOC stack.

Technologies: FortiSIEM · Regex · Syslog · Detection Engineering

Skills & Tools
SIEM & Monitoring

Splunk · FortiSIEM · Microsoft Sentinel · Wazuh · QRadar

Endpoint Security

Microsoft Defender for Endpoint · CrowdStrike Falcon · SentinelOne

Threat Intelligence

VirusTotal · AbuseIPDB · URLScan.io · Cisco Talos · Hybrid Analysis · MITRE ATT&CK

Automation & Dev

n8n · Python · PowerShell · REST APIs · RegEx · JavaScript

Detection Engineering

Sigma Rules · YARA · Correlation Rule Development · Parser Development · Use-case Design

Network & Pentest

Wireshark · Nmap · Burp Suite · Nessus · Metasploit · OpenVAS · Kali Linux

Certifications & Education
Certifications & Achievements
  • Microsoft SC-200 — Security Operations Analyst Associate
  • Techonquer Certified VAPT Practitioner (TCVP)
  • TryHackMe Security Engineer — 2025
  • TryHackMe SOC Level 1 — 2025
  • TryHackMe: Top 1% globally — 52 badges — 531+ day streak — 345+ labs
  • Blue Team Labs Online (BTLO): Top 6% globally
  • Introduction to Cybersecurity Certification — 2023
Education

Kakatiya University, Warangal
Bachelor of Commerce (Computer Applications) | July 2022 – May 2025

While my academic background is in commerce, my cybersecurity expertise has been built entirely through hands-on practice, certifications, and professional experience — demonstrating that skills and results matter more than a traditional CS pathway.

Get In Touch

Open to SOC roles, security automation projects, and cybersecurity collaborations. Based in Hyderabad, Telangana, India.

Made with