Monish Teja Kolli
SOC Analyst III (Cybersecurity) @ Sutter Health
About
I’m a Senior SOC Analyst and cybersecurity professional with over 10 years of experience protecting enterprise, cloud, and hybrid environments from evolving cyber threats. My work focuses on threat detection, incident response, and building resilient security operations that go beyond reactive defense. I specialize in leveraging SIEM platforms like Splunk, Microsoft Sentinel, and QRadar to detect and investigate advanced threats, combined with EDR/XDR tools such as CrowdStrike and Microsoft Defender for deep endpoint visibility and rapid response. I have hands-on experience in threat hunting using MITRE ATT&CK frameworks, enabling proactive identification of attacker behaviors including lateral movement, privilege escalation, and zero-day activity. A key part of my work involves automation and scalability. I design and implement SOAR-driven workflows using tools like Splunk Phantom and Cortex XSOAR, along with Python and PowerShell, to streamline alert triage and reduce response time. This allows security teams to focus on high-impact threats while improving overall SOC efficiency. I also bring strong expertise in cloud security across AWS, Azure, and Google Cloud, where I implement monitoring, detection, and posture management strategies using tools like AWS GuardDuty, Security Hub, and Microsoft Defender for Cloud. My experience extends to vulnerability management, digital forensics, firewall security, and compliance frameworks including NIST, ISO 27001, SOC 2, and HIPAA. Beyond technical execution, I’ve led and mentored SOC teams, developed detection use cases, and improved incident response processes through continuous tuning and threat intelligence integration. I’m passionate about building proactive security strategies, reducing risk, and staying ahead of emerging threats. I’m always open to connecting with professionals in cybersecurity, cloud security, and threat intelligence, and exploring opportunities to drive impactful security outcomes.
United States
Boston
Computer & Network Security
LAN/WAN Networking, Firewall & VPN Security,, AWS VPC Networking, Network Monitoring & Troubleshooting, OSPF & EIGRP Routing, Cisco ASA Firewall Management, LAN/WAN Network Administration, Network Monitoring (SolarWinds, SNMP), VLAN & Network Segmentation, VPN & Network Troubleshooting, BGP & OSPF Routing Protocols, AWS VPC / Cloud Networking, Network Security (Cisco ASA / Palo Alto Firewalls), Cisco Routers, ISO 27001, Network Security Implementation, Artificial Intelligence (AI), UX/UI, VMware, Microsoft Office
Experience

SOC Analyst III (Cybersecurity)
Sacramento, CA
Leveraged AI/ML-driven anomaly detection and UEBA using Splunk, Microsoft Sentinel, Exabeam, and LogRhythm to identify insider threats and anomalous behavior beyond signature-based detection. Conducted threat hunting and SOC investigations using SIEM tools such as Splunk, Elastic, and QRadar, aligning detections with MITRE ATT&CK to uncover indicators of compromise, lateral movement, and privilege escalation. Responded to zero-day exploits, APT campaigns, and ransomware incidents, collaborating with IT and DevOps teams to contain and remediate threats using tools like Carbon Black and Cortex XDR. Designed and implemented DLP strategies across cloud and SaaS platforms including Microsoft 365, AWS S3, and Google Workspace, reducing data exfiltration risks. Performed vulnerability assessments using Nessus and Qualys, integrating findings into SIEM for proactive alerting. Developed and fine-tuned SIEM correlation rules, dashboards, and detection use cases, improving monitoring and incident triage efficiency. Automated response workflows using SOAR tools like Splunk Phantom and Cortex XSOAR, reducing response times. Investigated endpoint alerts using EDR tools such as CrowdStrike and Microsoft Defender, performing root cause analysis and rapid containment. Managed incidents in ServiceNow and IBM Resilient, documenting actions and improving response processes. Correlated multi-source logs and optimized firewall and network controls to enforce least privilege and reduce attack surfaces. Implemented cloud security monitoring using AWS GuardDuty and Defender for Cloud to detect misconfigurations and threats. Developed SOC playbooks, integrated threat intelligence, and conducted security awareness training, strengthening overall cyber resilience and improving detection and response capabilities.

Senior SOC Analyst
Chicago, IL
As a seasoned Cybersecurity Leader, I have spearheaded enterprise-level threat detection and incident response across complex endpoint, network, cloud, and application environments. I possess deep expertise in orchestrating SOC operations using major SIEM platforms like Splunk, IBM QRadar, and LogRhythm, where I specialized in tuning correlation rules, designing executive dashboards, and automating workflows to enhance detection accuracy. My technical leadership extends to managing advanced EDR/XDR solutions—including CrowdStrike and Microsoft Defender—and optimizing perimeter defenses via Palo Alto, Fortinet, and F5 SSLO for deep traffic inspection. I am a proactive defender, leveraging the MITRE ATT&CK framework, Sigma rules, and integrated threat intelligence (Recorded Future, Anomali) to conduct sophisticated threat hunting. My commitment to rapid mitigation is evidenced by my development of comprehensive IR playbooks and SOAR automation scripts using Python and PowerShell, which streamlined log enrichment and containment efforts. Beyond reactive measures, I have led robust vulnerability management programs using Tenable, Qualys, and Burp Suite, conducting penetration tests and root cause analyses to harden security postures across AWS, Azure, and hybrid infrastructures. A collaborative leader, I have bridged the gap between Security, DevOps, and IT to implement Secure SDLC practices and OWASP testing. My experience encompasses securing the entire digital estate—from email security (Proofpoint, Abnormal) to Cloud Security Posture Management (Prisma Cloud). By mentoring Tier 1-3 analysts and implementing continuous process improvements via ServiceNow and JIRA, I have consistently transformed SOC operations into high-efficiency, intelligence-driven units that prioritize risk-based remediation and regulatory compliance (NIST, ISO 27001).

SOC Analyst / Cybersecurity Engineer
Valley Bank Wayne
New Jersey, United States
As a Cloud Security Specialist and SOC Lead, I have built robust detection and response architectures across multi-cloud and hybrid environments. I specialize in designing centralized log management pipelines using Google Cloud Pub/Sub, integrating them into enterprise SIEMs like Splunk, QRadar, and Elastic Stack for real-time correlation and hypothesis-driven threat hunting. My expertise lies in high-stakes incident response, where I lead the full lifecycle—from alert triage and log correlation to root cause analysis and recovery—ensuring strict adherence to SLAs. I have a proven track record of reducing response times by automating remediation workflows through AWS Lambda, Python scripting, and SOAR principles. I am deeply proficient in leveraging EDR/XDR platforms such as CrowdStrike Falcon and Microsoft Defender to investigate endpoint threats and contain lateral movement. To maintain a proactive defense, I integrate threat intelligence from platforms like MISP and ThreatConnect, while continuously fine-tuning SIEM correlation rules to minimize false positives. My cloud-native security experience is extensive, spanning the implementation of AWS Security Hub, GuardDuty, WAF, and Shield, alongside vulnerability management using Rapid7 InsightVM and Google Cloud Security Command Center. Beyond technical execution, I am a champion for governance and compliance. I have conducted comprehensive vendor assessments and internal audits against PCI-DSS, SOC 2, NIST CSF, and ISO 27001. By enforcing CIS Benchmarks, strengthening IAM through SAML 2.0/OAuth and MFA, and integrating security controls into CI/CD pipelines, I have successfully reduced organizational attack surfaces. My leadership is further demonstrated through the creation of operational dashboards tracking MTTD/MTTR metrics and delivering security awareness training to foster organizational resilience.

SOC & Network Security (SOC Engineer II)
New York City, NY
I am a Network Security Specialist with a proven track record of designing resilient architectures across on-premises and cloud environments. I specialize in Network Access Control (NAC), deploying Aruba ClearPass for role-based access and BYOD security, and leveraging Aruba AirWave and Central for wireless optimization. My perimeter defense expertise includes configuring IPSEC VPN tunnels, implementing Zone-Based Firewalls on Cisco ASA, and leading multi-vendor firewall cleanups (Check Point, Palo Alto). In the SOC, I manage full-lifecycle incidents using ServiceNow and JIRA. I am proficient in tuning SIEM policies (Splunk, QRadar, ArcSight) to enhance detection while reducing false positives. My investigative toolkit includes digital forensics using EnCase, FTK, and Cellebrite, alongside DLP and IPS solutions (Symantec, Forcepoint, Cisco Firepower) to design mitigation controls. I also utilize SOAR platforms like Demisto and Phantom to automate response actions. A strategic communicator, I bridge the gap between technical teams and leadership, providing briefings on incident analysis and risk. I have a strong background in governance, conducting assessments against NIST RMF and CIS Benchmarks. My experience extends to managing PKI and digital certificate lifecycles and providing remediation guidance. By collaborating with cross-functional stakeholders, I drive the remediation of key risk areas while upholding the highest standards of data integrity and confidentiality.

Application Security Analyst / Engineer
Integration Solutions
Hyderabad
As a versatile Security Officer and Assessor, I specialize in the full lifecycle of Application Security Testing and Risk Management Framework (RMF) implementation. I have extensive experience performing Static and Dynamic Application Security Testing (SAST/DAST) using industry-standard tools like HP Fortify and IBM AppScan. My technical expertise includes conducting manual penetration tests on web applications and executing rigorous security scans before production releases to identify, analyze, and remediate vulnerabilities. Additionally, I have managed cloud security configurations within AWS, specifically focusing on IAM and EC2/EC3 instance security to ensure a hardened cloud infrastructure. I am deeply proficient in federal compliance and FISMA metrics, having led system categorization kickoffs for agencies like the FAA in accordance with NIST requirements (Low, Moderate, High). My background as both an ISSO and Assessor allows me to bridge the gap between documentation and technical verification. I have authored and maintained critical security artifacts, including System Security Plans (SSP), Security Assessment Reports (SAR), Plans of Action and Milestones (POA&M), and Executive Summaries (ES). By executing examine, interview, and test procedures per NIST SP 800-53A Rev 4, I ensure that all cybersecurity policies are adhered to and that required controls are effectively implemented. Furthermore, I have contributed to the design of Ongoing Authorization (OA) programs to maintain continuous monitoring of system security postures. I am skilled at managing risk management calendars and coordinating with stakeholders to deliver actionable security insights. Whether performing security test and evaluation (ST&E) assessments or managing annual testing requirements, my focus remains on reducing risk through a blend of automated scanning, manual assessment, and robust policy enforcement.

Network Engineer
Hyderabad
I am a Senior Network Engineer with extensive experience in designing, implementing, and securing global enterprise infrastructures. I specialize in high-availability solutions and application delivery, with deep expertise in F5 BIG-IP (LTM/GTM) and NetScaler technologies. My work includes configuring complex load-balancing strategies—such as priority-based pool activation and global site load balancing—and executing hardware refreshes from legacy systems to high-performance Viprion chassis. I am highly proficient in core routing and switching, managing advanced BGP attributes (Local Preference, MED, Route-Reflectors) and redistributing OSPF and EIGRP across Cisco ASA firewalls to optimize traffic flow and network stability. On the security front, I have a strong background in identity management and perimeter defense. I implemented Cisco ACS for wired and wireless authentication using certificates and MAB for company assets, ensuring a secure access layer. My firewall experience spans the administration of Cisco ASA, Fortinet, and Check Point systems, including provisioning Check Point firewalls integrated within AWS cloud environments. I have also led the redesign of internet connectivity infrastructure to meet increasing bandwidth demands while maintaining strict security and high-availability standards. I leverage industry-leading monitoring and documentation tools, including SolarWinds, Cisco Prime, NetBrain, and Splunk, to track network health and performance. By maintaining meticulous documentation through MS Visio and MS Project, I ensure all LAN/WAN diagrams and configurations are accurate and accessible. Whether resolving complex internal customer tickets or managing large-scale infrastructure deployments, I focus on delivering scalable, secure, and high-performing network solutions.
Monish Teja Kolli's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.


