Detection & Response Engineering

Soma Nitin

Detection & Response Engineer

Cybersecurity engineer with 10+ years of experience across Endpoint Detection & Response, Extended Detection & Response, threat detection, security investigations, and security operations — engineering detection capabilities and response workflows that hold up in enterprise environments.

Detect Investigate Respond Build
10+Years of Experience
500+EDR Customers Supported
20+XDR Customers Onboarded
MultipleSecurity Platforms

Engineering security capabilities that work in the real world.

I bring a combination of hands-on detection and response engineering, customer security assessments, endpoint investigations, and SOC leadership to improve security visibility, detection coverage, and response effectiveness.

My work spans endpoint security platforms, XDR onboarding, custom detection development, prevention configuration, response automation, threat hunting, and operational improvement across enterprise environments.

Security Operations

Leading SOC shift operations, incident response, and 24/7 monitoring across enterprise environments.

Detection Engineering

Building custom detections and response workflows across leading EDR and XDR platforms.

Customer Enablement

Onboarding and supporting 500+ EDR and 20+ XDR customers through assessments and configuration.

Continuous Improvement

Driving SOP improvements, workflow automation, and knowledge transfer to raise operational maturity.

Professional experience

Detection & response • SOC • Security operations

Principal Security Engineer

Proficio

Sep 2022 — Present

Endpoint Detection & Response

  • Engineered and operationalized EDR/XDR capabilities across customer environments, supporting endpoint visibility, policy configuration, detection, investigation, and response.
  • Onboarded and supported 20+ XDR customers and 500+ EDR customers across enterprise security environments.
  • Designed, configured, and maintained endpoint security policies, prevention controls, exclusions, application controls, and policy assignments across CrowdStrike Falcon, SentinelOne, VMware Carbon Black, and Microsoft Defender for Endpoint.
  • Developed custom detections in Microsoft Defender for Endpoint and built CrowdStrike Fusion workflows and SentinelOne STAR rules for threat identification and response automation.
  • Performed initial technical assessments of customer environments, reviewing security configurations, endpoint policies, prevention controls, and operational readiness.
  • Investigated endpoint alerts and phishing activity using EDR telemetry, supporting triage, escalation, containment recommendations, and response.
CrowdStrikeSentinelOneMicrosoft DefenderCisco XDR

SOC Shift Lead

Uber

Apr 2020 — Sep 2022

Security Response & Investigations

  • Led SOC shift operations supporting monitoring, incident response, threat investigations, and endpoint security operations.
  • Coordinated end-to-end incident response from triage and validation through containment and remediation.
  • Guided analysts through complex investigations and high-priority escalation decisions.
  • Conducted threat hunting and host-based investigations using SIEM, EDR, and threat intelligence.
  • Improved SOC effectiveness through EDR optimization, workflow automation, SOP improvements, and knowledge transfer.
SOC LeadershipThreat HuntingIncident ResponseSIEM

Security Analyst II

Diyar United Company

May 2018 — Apr 2020

Threat Intelligence & Investigations

  • Reviewed alarms and reported inaccuracies to the engineering team for correction.
  • Monitored and analyzed security events across SIEM, network, host, firewall, application, and database logs.
  • Investigated alerts, scan results, logs, and files throughout the incident response lifecycle.
  • Reviewed SIEM use cases and recommended improvements to log correlation and security analytics.
  • Supported analyst onboarding and knowledge transfer in attack and malware analysis.

Senior Executive — Cyber Defence Operations

Vodafone

Jul 2017 — May 2018
  • Supported cyber defence operations, security monitoring, incident analysis, and response activities across enterprise security environments.
  • Investigated security alerts, assessed potential threats, and escalated incidents in accordance with established response procedures.
  • Collaborated with security teams and stakeholders to support timely incident handling and operational improvements.

First Line Security Support Engineer — CDO

Vodafone

May 2015 — Jun 2017
  • Provided first-line SOC support through alert monitoring, initial analysis, triage, and escalation.
  • Created and tracked incident tickets, coordinating with relevant teams to support investigation and resolution.
  • Supported enterprise security monitoring technologies and day-to-day SOC operations, including foundational troubleshooting.

Core capabilities & technology

Detection Engineering

Custom detections, detection rules, threat identification, detection coverage, and analytics improvement.

EDR & XDR Engineering

Platform onboarding, policy design, prevention controls, endpoint health, configuration, and operational readiness.

Response Automation

CrowdStrike Fusion workflows, SentinelOne STAR rules, response workflows, and operational automation.

Threat Hunting & Investigations

Endpoint telemetry analysis, host-based investigations, threat intelligence, triage, escalation, and containment recommendations.

SOC Operations & Leadership

Shift leadership, incident coordination, SOP improvement, analyst mentoring, stakeholder collaboration, and knowledge transfer.

Security Assessments

Customer environment reviews covering policies, prevention, exclusions, detections, configurations, and operational readiness.

Platforms & tools

CrowdStrike FalconSentinelOneVMware Carbon BlackMicrosoft Defender for EndpointCisco AMPTrend MicroPalo Alto Cortex XDRCisco XDRLogRhythmELK StackArcSightProofpointCisco UmbrellaIBM ResilientServiceNowJiraAWS

Professional certifications

01Palo Alto Certified XDR EngineerCortex
02CrowdStrike Certified Falcon Administrator
03SentinelOne Certified Administrator
04SentinelOne Incident Response
05Trend Micro Vision One for Administrators
06Certified Ethical HackerCEH
07MITRE ATT&CK Defender
08CompTIA Security+
09AWS Certified Cloud Practitioner

Projects & impact areas

Automation02

Detection and response workflows

Designed and built CrowdStrike Fusion workflows, SentinelOne STAR rules, and custom detections to support repeatable threat identification and response use cases.

FusionSTARCustom detections
Security Operations03

SOC optimization & investigations

Improved operational effectiveness through investigation guidance, threat hunting, EDR optimization, SOP improvements, incident documentation, and knowledge transfer.

SOCThreat huntingIR

Let's talk security engineering.

Open to conversations around detection engineering, EDR/XDR, security operations, incident response, and technical leadership opportunities.