Prasanna K H — Incident Response & Security Operations Engineer
Incident Response & Security Operations Engineer
Incident Response & Security Operations Engineer
Incident Response and Security Operations Engineer with 4 years of experience in SOC, MDR, and enterprise security operations. Proven expertise in managing end-to-end security incident response processes, including identification, containment, eradication, recovery, and post-incident analysis. Highly skilled in SIEM management, threat detection, alert triage, evidence preservation, and incident documentation in accordance with NIST and ISO 27001 standards. Effective in cross-functional collaboration, executive communication, and continuous improvement of incident response playbooks.
Supported infrastructure monitoring by performing Windows Server health assessments and basic troubleshooting.
Assisted with user access verification, mailbox monitoring, and endpoint security checks.
Shadowed SOC analysts during phishing investigations and escalated security incidents as appropriate.
Developed foundational knowledge in virtualization technologies (Hyper-V, VMware) and Azure fundamentals.
Engineer I – Cyber and Tech Management
Wipfli India LLP
Oct 2022 — Sep 2025 · 3 yrs
Full-timeHybrid
Conducted daily SOC operations, including alert correlation, triage, and first-level incident response within defined SLAs.
Contributed to security incident investigations through log analysis, identification of indicators of compromise, and escalation of verified threats.
Assisted in containment and remediation efforts for phishing, malware, and unauthorized access incidents.
Provided support for Windows Server administration, Microsoft 365 security operations, endpoint protection, and infrastructure health monitoring.
Assisted with backup verification, recovery testing, and service restoration processes.
Gained practical experience across SOC, TOC, and Service Desk functions, enhancing enterprise operational resilience.
Engineer II – Cyber and Tech Management
Wipfli India LLP
Oct 2025 — Present · 1 yr
Full-timeHybrid
Served as Incident Response Coordinator across multiple client environments, managing investigation, containment, recovery, and remediation of security incidents.
Functioned as primary liaison during active incidents, coordinating efforts among SOC, TOC, client IT teams, and executive leadership.
Led end-to-end SIEM onboarding and sensor deployment projects, integrating diverse log sources and validating alerts to improve detection capabilities.
Directed an IT Roadmap Project that identified security gaps, risks, and new service opportunities to support customer engagement and adoption.
Managed a Windows Update and Patch Management Project that reduced vulnerabilities and enhanced compliance with security baselines.
Designed and maintained incident response SOPs and security playbooks to ensure audit readiness and operational consistency across SOC/TOC teams.