Romal Shah

Romal Shah

About

Detail

Senior Information Security Consultant
Gujarat, India

Timeline


work
Job

Résumé


Jobs verified_user 0% verified
  • Sysco
    Senior Information Security Consultant
    Sysco
    May 2023 - Current (3 years 1 month)
    Acted as the primary escalation point for high-severity and critical cybersecurity incidents across enterprise environments. Led cross-functional IT projects, delivering high-impact results through strategic planning, stakeholder collaboration, and agile execution methodologies. Performed deep-dive investigations to assess the impact, scope, and root cause of advanced security incidents. Developed SOC triage scripts to provide knowledge transfer and training for OT staff on finer details of analysis of UEBA data and the Exabeam Platform. Leading Special Projects - Information Security Assessments for Merger & Acquisitions, researching Cyber Security Products for Fusion Center SOC, enhancing Cyber Security Threat Intel & Global SOC capabilit
  • Tesla
    Senior Security Engineer
    Tesla
    Jan 2021 - Apr 2023 (2 years 4 months)
    Support and assist the CSOC in their investigations of cyber security events to identify potential security incidents. Responsibility to Operations Center environment team such as: Computer Emergency Response Team (CERT), Computer Incident Response Team (CIRT) Develop cyber security ThreatConnect with SOAR (Siemplify) which includes detection signatures across various cyber security platforms. Delivered actionable threat detection insights to improve the client's incident response maturity. Integrated UEBA platforms with SIEM tools like Splunk ES, Exabeam, and ArcSight to correlate behavioral anomalies with security events for enhanced threat detection. Designed and implemented custom risk scoring models to prioritize alerts based on user a
  • Citigroup
    Information Security Engineer
    Citigroup
    Jan 2017 - Dec 2020 (4 years)
    Ensure the SOC analyst team is providing excellent customer service and support. Monitor firewall, NIDS and HIDS logs though the use of a SIEM tool (ArcSight). Identified and mitigated Advanced Persistent Threats (APTs) by leveraging network telemetry and endpoint data. Tuned SIEM correlation rules, use cases, and dashboards to improve detection accuracy and reduce false positives. Recommended enhancements to firewall policies, IDS/IPS signatures, and endpoint protection configurations. Implemented proactive security hygiene improvements and policy enforcement measures. Leveraged Exabeam Advanced Analytics to detect lateral movement, credential misuse, and privilege abuse in enterprise environments. Conducted threat hunting exercises using
  • B
    Cyber Security Analyst
    Berkshire Hathaway
    Jul 2014 - Dec 2016 (2 years 6 months)
    Served as Tier 1 support in area of network intrusion prevention and detection in CSOC under SMT. Understanding of use-case development specific to threat intelligence and fusion (Cyber security, Fraud) Consolidating analysis of suspicious Splunk data security event logs (Windows Defender, AppLocker, and Audit Events). Critical Incident Response Team (CIRT) of contact for Data Loss Prevention security breaches Enterprise Logging - Splunk, Loggly, SumoLogic Utilizing OSINT techniques for emerging threats including threat hunting on the dark web and ToR networks Hunting, identifying and profiling threat actors, Advanced Persistent Threats (APT's) and TTPs Report common and repeat problems, observed via trend analysis, to SOC management and pr
Education verified_user 0% verified
  • DePaul University
    Bachelor's Degree of Science in Networking Engineering and Security
    DePaul University
    Chicago, IL