SATYA
NALLAM
Securing enterprise SOCs and engineering secure CI/CD pipelines — 6.5+ years across security operations and DevSecOps.
// detect impossible travel + secret in MR SigninLogs | where ResultType == 0 | extend geo = parse_json(LocationDetails) | summarize dcount(geo.country) by UserPrincipalName, bin(TimeGenerated, 10m) | where dcount_geo_country > 1 // secret detection: GitLab secret push protection
About
Security engineer and DevSecOps owner at Human Managed, a managed security services provider — securing GitLab CI/CD pipelines, ArgoCD GitOps and container registries across 8+ product repos, running vulnerability management org-wide, and driving SOC 2, ISO 27001 and ISO 42001 work. Before that, 24x7 SOC operations at TCS across Microsoft Sentinel, Google SecOps, Splunk, CrowdStrike and SentinelOne. I build security into engineering pipelines instead of adding it at the end.
Skills
Experience
- Own DevSecOps for the organisation after a senior engineer's exit: GitLab CI/CD, ArgoCD GitOps, container registries and pipeline scanning across 8+ product repos.
- Run GitLab security scanning (SAST, secret detection, SCA, container); triaged a backlog of ~1,870 findings and cleared every critical SLA breach.
- Built an SLA-tracked vulnerability management process on the GitLab API with Slack escalation to remediation owners.
- Administer GitLab security controls: access reviews, offboarding, permissions, CODEOWNERS, protected branches, MR approval rules, CI token rotation.
- Operate ArgoCD GitOps for Kubernetes delivery and manage the Harbor registry including supply-chain review and image scanning.
- Drive compliance remediation in Vanta across SOC 2, ISO 27001 and ISO 42001.
- Analyse 100+ daily alerts across Sentinel, Google SecOps, Splunk, CrowdStrike, SentinelOne and Trellix, end to end.
- Tune MITRE-mapped SIEM detections for 35% fewer false positives; AI-assisted triage cut investigation time 40% and MTTD 45%.
- Automate incident response and reporting in Python — 60% less manual effort, reports from hours to minutes.
- Monitored 500K+ daily security events across Microsoft Sentinel, M365 Defender and SentinelOne.
- Investigated and resolved 150+ incidents: malware, credential compromise, unauthorised access, data breach investigations.
- Improved detection efficiency 25% through KQL development, threat intel analysis and CVE triage.
- Cut false positives 30% via alert correlation, tuning and behavioural analysis.
- Mentored 4 junior analysts; 5/5 performance rating and an On-the-Spot Award for critical incident management.
Projects
Certifications
Education
Let's build something secure.
Security engineer who ships detection and DevSecOps that developers actually use. If you're working on SOC modernisation, pipeline security, or compliance that needs real evidence — let's talk.