Security engineering & DevSecOps · Hyderabad, India · currently at Human Managed
AboutSkillsExperienceProjectsCertificationsContact
Security Engineer · DevSecOps

SATYA
NALLAM

Securing enterprise SOCs and engineering secure CI/CD pipelines — 6.5+ years across security operations and DevSecOps.

Hyderabad, India — remote [email protected]
500K+
daily events monitored
150+
incidents resolved
1,870
findings triaged
35%
false-positive reduction
45%
MTTD reduction
60%
manual effort automated
sentinel_live.kql — SecOps
Active Detection
Impossible Travel + Secret Scan
// detect impossible travel + secret in MR
SigninLogs
| where ResultType == 0
| extend geo = parse_json(LocationDetails)
| summarize dcount(geo.country) by UserPrincipalName, bin(TimeGenerated, 10m)
| where dcount_geo_country > 1
// secret detection: GitLab secret push protection
● live — 4 matchesMITRE T1078 · T1552.001
Repo Coverage
8+ repos
Alerts / Day
100+
SLA Breaches
0 critical
sentinel :: 12:44:09 IST · auto-triaged42ms p95

About

Security engineer and DevSecOps owner at Human Managed, a managed security services provider — securing GitLab CI/CD pipelines, ArgoCD GitOps and container registries across 8+ product repos, running vulnerability management org-wide, and driving SOC 2, ISO 27001 and ISO 42001 work. Before that, 24x7 SOC operations at TCS across Microsoft Sentinel, Google SecOps, Splunk, CrowdStrike and SentinelOne. I build security into engineering pipelines instead of adding it at the end.

Built AI-assisted triage that cut investigation time 40% and MTTD 45%
Tuned MITRE-mapped SIEM detections, 35% fewer false positives
Took over DevSecOps solo and cleared a 1,870-finding backlog
Mentored 4 junior analysts, 5/5 performance rating at TCS
How I Work
Detection engineering
KQL, MITRE ATT&CK, correlation, tuning for signal not noise.
Automation first
Python and platform APIs; if I do it twice, I script it.
Shift left
Security gates inside the pipeline, with fixes written for developers.
Evidence over assertion
Compliance controls backed by real monitoring evidence.
Incident command
P1/P2 handling, containment, and a written runbook afterwards.

Skills

SIEM, SOC & Detection Engineering
11 skills
Microsoft SentinelGoogle SecOpsSplunkM365 DefenderKQLMITRE ATT&CKDetection EngineeringIncident ResponseLogging & MonitoringAlert CorrelationSecurity Dashboards
DevSecOps & CI/CD Security
10 skills
GitLab CI/CDSASTSCASecret ScanningDependency ScanningContainer SecurityArgoCDGitOpsKubernetesHarbor
Cloud, Infrastructure & Endpoint
10 skills
Azure SecurityGoogle Cloud SecurityIAMSystem HardeningZscalerEndpoint SecurityEDR/XDRCrowdStrikeSentinelOneTrellix
Vulnerability, Compliance & Automation
11 skills
Vulnerability ManagementCVE TriageCVSSCISA KEVSOC 2ISO 27001ISO 42001VantaRisk AssessmentPythonBash

Experience

CurrentRemote
Human Managed — CyberOps Analyst | DevSecOps Engineer
Own DevSecOps across 8+ product repos, plus 24x7 multi-tenant SOC coverage
04/2025 to Present
  • Own DevSecOps for the organisation after a senior engineer's exit: GitLab CI/CD, ArgoCD GitOps, container registries and pipeline scanning across 8+ product repos.
  • Run GitLab security scanning (SAST, secret detection, SCA, container); triaged a backlog of ~1,870 findings and cleared every critical SLA breach.
  • Built an SLA-tracked vulnerability management process on the GitLab API with Slack escalation to remediation owners.
  • Administer GitLab security controls: access reviews, offboarding, permissions, CODEOWNERS, protected branches, MR approval rules, CI token rotation.
  • Operate ArgoCD GitOps for Kubernetes delivery and manage the Harbor registry including supply-chain review and image scanning.
  • Drive compliance remediation in Vanta across SOC 2, ISO 27001 and ISO 42001.
  • Analyse 100+ daily alerts across Sentinel, Google SecOps, Splunk, CrowdStrike, SentinelOne and Trellix, end to end.
  • Tune MITRE-mapped SIEM detections for 35% fewer false positives; AI-assisted triage cut investigation time 40% and MTTD 45%.
  • Automate incident response and reporting in Python — 60% less manual effort, reports from hours to minutes.
Tata Consultancy Services — SOC Analyst
24x7 enterprise SOC monitoring and incident response
03/2022 to 03/2025
  • Monitored 500K+ daily security events across Microsoft Sentinel, M365 Defender and SentinelOne.
  • Investigated and resolved 150+ incidents: malware, credential compromise, unauthorised access, data breach investigations.
  • Improved detection efficiency 25% through KQL development, threat intel analysis and CVE triage.
  • Cut false positives 30% via alert correlation, tuning and behavioural analysis.
  • Mentored 4 junior analysts; 5/5 performance rating and an On-the-Spot Award for critical incident management.
Grama Ward Sachivalayam — Panchayat Secretary Grade VI, Digital Assistant
Kothapeta — Digital governance platforms and confidential records for 3,000+ citizens
11/2019 to 02/2022

Projects

AI-Assisted CI/CD Security Scanning Pipeline
Semgrep SAST inside GitLab CI with AI-assisted triage, so scans run on every merge request and developers get remediation guidance in the MR itself.
1,870 findings triagedzero critical SLA breachesSlack auto-escalation
GitLab CISemgrepPythonSlack API
AI SOC Analyst Agent
An alert-triage agent on Azure AI Foundry that enriches alerts and does first-pass analysis, standardising triage quality across the team.
40% faster investigations45% lower MTTDteam workshop delivered
Azure AI FoundrySentinelKQLPython
SLA-Tracked Vulnerability Management
A GitLab API service that tracks every finding against its SLA and escalates to the owning team in Slack before it breaches.
org-wide coverageowner-routedbreach-free
GitLab APIPythonSlack
Internal Web Tools
A timesheet and leave app, and a security-tooling survey app with an executive report, both shipped solo end to end.
used by the teambuilt soloshipped in days
ReactSupabaseCloudflare Pages

Certifications

Verified
Microsoft Certified: Security Operations Analyst Associate
09/2025 to 09/2027
Microsoft
ID DB4AB93DF65509F7
Verified
Google Cloud Certified Professional Security Operations Engineer
10/2025 to 10/2027
Google Cloud
ID 254be7ec00914aeeb0f7ed78d1e0bbbc
Verified
Certified Cybersecurity Educator Professional (CCEP)
11/2025 to 08/2026
Red Team Leaders
Credential on file
Verified
Proofpoint Certified AI Email Security Specialist
09/2025 to 09/2027
Proofpoint
Verified credential

Education

B.Tech, Electrical & Electronics Engineering
Aditya University (JNTUK), Surampalem
Full-time06/2016 to 05/2019
Diploma, Electrical & Electronics Engineering
Aditya Polytechnic, Surampalem
Diploma06/2013 to 05/2016
Open to interesting problems

Let's build something secure.

Security engineer who ships detection and DevSecOps that developers actually use. If you're working on SOC modernisation, pipeline security, or compliance that needs real evidence — let's talk.

Hyderabad, India — remoteIST
usually replies within a day~24h
What I'm Working On
SLA-tracked vulnerability management
Across every product repo, with Slack escalation before breach.
Closing SOC 2, ISO 27001 and ISO 42001 gaps
Control gaps in Vanta — access, change control, monitoring evidence.
Detection tuning
Drops false positives without losing coverage, MITRE-mapped.
8+ repos secured
100+ alerts/day
1,870 findings triaged
6.5+ years