Security Engineer · Detection & Response

Gokul
L

Chennai, India · Open to opportunities

"I break assumptions. Then I build detections for what slips through."

Scroll
01

About

I'm a security professional with 5+ years of experience working across enterprise SOC, security consulting, and MSSP environments. My work spans incident investigation, threat analysis, and identifying security gaps that automated systems routinely miss.

I don't wait for alerts to tell me something is wrong. I look at how controls are configured, where assumptions are made, and where those assumptions break. That's where the real risk lives — in the gaps between policy and behavior.

I've worked with organizations across banking and advisory sectors, operating in 24×7 environments where precision matters. Along the way I've built internal tooling to improve how security teams triage and investigate incidents.

Experience
5+
Years in security operations
Focus Area
D&R
Detection & Response
Environment
24×7
Enterprise SOC
Tools Built
02
iRECON & Flow-ed
02

Notable Findings

Access Control
Application Control Bypass via Policy Gap
Identified a misconfiguration in application control policy that created an unintended execution path for unauthorized software — enabling potential data exfiltration from managed endpoints without triggering standard detections.
01
Unsanctioned Tooling
Unauthorized AI Automation Agent in Enterprise Perimeter
Detected the presence of an unsanctioned AI automation tool operating within the enterprise environment. Documented associated risks including unmonitored outbound communication and policy violations not captured by existing controls.
02
AI Risk Surface
Shadow AI Development Extensions — Prompt Injection & Data Exposure
Found unauthorized AI-assisted IDE extensions in active use across endpoints. Identified the associated risk surface: potential sensitive data exposure, prompt injection vectors, and data poisoning risks in development workflows.
03
Anomalous Behavior
Internal Reconnaissance Activity Incorrectly Permitted
Caught anomalous internal scanning activity that had been allowed through a misconfigured permissive rule. Confirmed the behavior was unauthorized, corrected the rule, and took steps to block further activity and prevent recurrence.
04
03

How I Think

Research & Detection Philosophy
Attacker behavior over alert volume

I focus on understanding how attackers actually operate — TTPs, choke points, blind spots — not just what signature fired. Alerts are symptoms. Behavior is the disease.

Look for what controls assume

Every security control is built on assumptions. I look for where those assumptions don't hold — that's where gaps live, often silently, for months before someone finds them the hard way.

Curious about failure modes

I want to understand how systems fail, not just how they work when everything goes right. The interesting security problems are in edge cases, misconfigurations, and unexpected interactions.

Findings become detections

A finding that doesn't produce a better detection or a closed gap is just a report. I try to close the loop — turning what I discover into something that makes the environment harder to exploit.

04

Projects

Security Intelligence · Internal Tool
iRECON
A security intelligence and alert scoring system built for SOC analysts. iRECON enriches incoming alerts with contextual data, helping analysts make faster, more confident triage decisions — distinguishing genuine threats from noise without manual lookups.
Alert Enrichment Triage Intelligence SOC Tooling Risk Scoring
Visit irecon.vercel.app →
Workflow Engineering · Internal Tool
Flow-ed
A flowchart-based tool for building SOC investigation workflows. Flow-ed lets analysts construct and share structured investigation logic for complex incidents — standardizing how teams approach different attack scenarios and reducing analyst-to-analyst inconsistency.
Incident Investigation Decision Trees Workflow Builder SOC Tooling
05

Skills

Detection & Response
Threat Hunting
Incident Response
MITRE ATT&CK
Log Correlation
Malware Triage
SIEM / EDR
Splunk
IBM QRadar
CrowdStrike Falcon
Microsoft Defender
SentinelOne
Tanium
McAfee ESM · Fortinet
Threat Intelligence
Threat Intelligence
OSINT
VMRay · Fidelis
CVE Analysis
Symantec DLP
AI Risk Modeling
Systems / Scripting
Linux (RHEL · Ubuntu)
Python
Bash
SPL Queries
Server Administration
06

Let's connect

Open to Security Engineer roles in detection, threat analysis, and incident response. Let's talk.