Security Operations · Dublin, IE

Hemanth Kori

RSOC Operator · Detection Engineer

I run the Regional Security Operations Centre for a NASDAQ-listed semiconductor company — triaging alerts, engineering detections, and turning signal into proof. This site is the proof.

scroll ↓
01 — Who I am

The operator behind the alerts

RSOC Operator at Synopsys covering the EMEA region — triaging 800+ alerts a shift across SIEM, CCTV/VMS and access control, and building the detections, dashboards and pipelines that explain them. Published time-series researcher. CompTIA Security+ (in progress).

Stamp 1GSecurity+ (in progress)Insider Threat Foundations
Trajectory
  1. 2025—
    RSOC Operator · Synopsys
    24/7 Regional SOC covering EMEA — SIEM, CCTV/VMS (Genetec/Milestone), access control (C•CURE 9000), ServiceNow, Everbridge.
  2. 2024
    Operations Manager · Appache Food & Health
    Led a 10+ team; cut waste 15% and lifted efficiency 20% with Excel/SQL + Power BI dashboards.
  3. 2023
    Data Research Analyst · upGrad
    ARIMA/SARIMA forecasting, credit-risk and ride-share demand models; published CO₂ research (DOI).
  4. 2022
    SOC Analyst Intern · Targe Cyberspace
    SIEM monitoring, phishing/malware analysis, vulnerability assessment aligned to OWASP.
  5. 2021
    VAPT Trainee
    Specialised training in vulnerability assessment, penetration testing and OWASP Top 10.
02 — Capabilities

What I bring to a SOC

SIEM Triage (Splunk / Sentinel)92
Incident Response90
MITRE ATT&CK Mapping88
Log Analysis & Correlation86
Detection Engineering (KQL)85
Python / SQL Pipelines84
Power BI / Tableau83
Threat Hunting82
CCTV / VMS / Access Control80
OWASP / Vuln Assessment74
03 — The proof

Detections I've engineered

Real analytics rules and tooling — mapped to MITRE ATT&CK, with the honest story of what fired, what didn't, and why.

Brute-Force Authentication

T1110 · Credential Access
live

11,970 failed logons against a single account on one host within minutes.

Threshold: 10 failures / 5 min. Fires as a scheduled analytics rule with entities mapped for one-click pivot to host & account.

Impossible Travel

T1078 · Initial Access
live

Same account signs in from Dublin then Lagos 35 minutes later — implied 9,051 km/h.

Geo-velocity rule with entity mapping; raised as an incident with account + IP entities for fast triage.

Privileged Activity — Out of Hours

T1078.003 · Privilege Escalation
tuning

Time-based rule returned zero rows — collector was stamping ingest time, not event time.

Lesson captured: a rule on collapsed timestamps looks healthy but fires on nothing. Now gated on true event time.

Phishing Email Triage Scorer

T1566 · Detection
blueprint

CLI that scores auth, sender identity, payload and language on a suspicious .eml and shows its reasoning.

Phish scores 100/100, a legitimate overdue-invoice chase scores 10/100 — a tool that flags everything trains analysts to ignore it.

DMARC Policy Drift Watch

T1595 · Defense Evasion
blueprint

Incident root cause was a parked p=none DMARC policy letting failed-SPF mail through.

Proposed control-health monitor that alerts when a domain's DMARC drops below p=quarantine.

04 — Build log

Selected work

05 — Voice

Writing & talks

06 — Let's talk

Open to SOC & detection roles

Targeting SOC Analyst, Security Operations, GSOC and detection engineering roles in Ireland and remote EU. Stamp 1G — full right to work, no sponsorship required.

[email protected]
Direct links
  • Location: Dublin, Ireland
  • Status: Actively applying · interviewing-ready
  • Clearance: Stamp 1G