Akash Raj

Security Analyst II, Cyber Defense

Hi, I'm Akash. I'm a security analyst in the Niagara Region of Ontario, and I work the defensive side of security: incident response, threat hunting, and detection engineering.

This site is the informal version of my resume and my LinkedIn profile. Same facts, fewer buzzwords, and a bit more about how I actually work.

Resume (PDF) | LinkedIn |

$ whoami
akash raj | security analyst ii, cyber defense
$ cat focus.txt
incident response | threat hunting | detection engineering
$ ls ~/stack
sentinel  defender-xdr  crowdstrike-falcon  azure  cymulate
$ 

About

I didn't set out to work in security. My first job was building websites and web applications, and I kept finding the security problems more interesting than the features I was shipping. In 2019 I moved to Ontario for a post-graduate diploma at Conestoga College, spent a while working flow operations at Loblaw to pay for it, and then worked my way into IT support. I joined a security team in 2022 and I've been on the blue side since.

These days I'm on Intact's Cyber Defense team, and I'm the Tier III escalation point. In practice that means when an alert is ambiguous enough that nobody wants to call it, it lands with me. I work out whether it's real, contain it if it is, and then write up what happened and what we're changing so it doesn't land on my desk the same way twice.

The work I'm proudest of is the unglamorous kind. I rewrote security policies into something people could actually follow, which cut unauthorized access by 75% and saved about $20K a year in breach costs. I wrote patch management scripts that took patching time down by 90%. I ran 200+ vulnerability tests that reduced our risk exposure by 30% and cut remediation times by 40%. And I built the security training programme, which raised compliance by 25% and cut phishing incidents by half.

What I actually enjoy is the detection side. A rule that fires all day is a rule nobody reads, and a noisy queue is how you miss the one alert that mattered. I've spent a lot of time in Microsoft Sentinel getting our rules down to the ones worth waking someone up for. I also run monthly breach and attack simulations, on the theory that the only honest way to test a control is to attack it yourself.

What I enjoy less is writing playbooks. I've written twelve of them anyway, because process is the thing that holds up at 3 a.m. when nobody can remember who to call.

That's about four years in security and five-plus in IT, across insurance and digital signage. Before all of this I did IT support and web development, which is why I'm comfortable moving between the SOC and the infrastructure teams instead of throwing tickets over the wall.


What I work with

Incident response and SOC

Tier III escalation and investigation, detection through containment and remediation, post-incident review, root cause analysis, IR playbook and SOP authoring, 24/7 shift operations and handover, MITRE ATT&CK aligned triage, tabletop exercise design and facilitation.

Threat hunting and detection engineering

Cyber Threat Hunting (CTH), hypothesis-driven hunting, breach and attack simulation with Cymulate, detection rule tuning, false positive reduction, sandbox and malware triage (any.run, Joe Sandbox, hybrid-analysis), threat intelligence enrichment (VirusTotal, MISP, Recorded Future, GreyNoise).

Vulnerability management

Vulnerability assessment, Qualys VMDR, Qualys Patch Management, patch automation, emerging vulnerability triage, risk-based remediation.

Identity and access management

Identity and Access Management (IAM), privileged access review, least privilege enforcement, access control audits, user exemption handling.

Platforms and tooling

Microsoft Sentinel (NGSIEM), Microsoft Defender for Endpoint, Defender XDR, CrowdStrike Falcon, Rapid7, Jira, Confluence.

Cloud and infrastructure

Microsoft Azure (AZ-500, AZ-104), Azure security baselines, Intune and Group Policy, Windows and Linux endpoint management.

Scripting and automation

PowerShell, Python, Shell and Bash, mostly for detection support, patch automation, and taking the boring parts out of recurring security work.


Experience

Security Analyst II, Cyber Defense

Intact | Mississauga, ON | January 2026 to Present

Promoted from Security Analyst after 10 months.

  • Tier III escalation point for the incidents other analysts cannot close. I take them from detection through containment and remediation, then write the post-incident review.
  • Retested 150+ penetration test findings and confirmed every high and critical issue was closed before it reached production.
  • Run monthly Cymulate breach and attack simulations across network and endpoint, which surfaced 25% more control gaps than our alert-driven process did.
  • Tune Microsoft Sentinel (NGSIEM) detection rules. False positive volume is down 30% and the rules that matter fire more reliably than they did a year ago.
  • Triage emerging vulnerabilities when public disclosure lands. 40+ so far, each with a risk reassessment inside 24 hours.
  • Wrote and ran 5 cross-functional tabletop exercises covering detection, containment, and remediation. Simulated MTTR dropped 15%.
  • Wrote 12 incident response playbooks and SOPs. Junior analyst onboarding time is down 40% since they went in.

Security Analyst, Cyber Defense

Intact | Mississauga, ON | March 2025 to December 2025

  • Worked rotating 24/7 shifts on the SOC escalation ladder, triaging and containing incidents and handing advanced cases up with the evidence, timeline, and impact already documented.
  • Rolled out Azure security baselines across 70+ affiliates, tightening compliance posture and reducing incident risk across the organization.
  • Built PowerShell and batch automation for recurring security operations work, saving 20+ hours a month.
  • Managed the CrowdStrike Falcon endpoint inventory, improving visibility into stray and unmanaged assets and holding protection coverage at 99%.
  • Wrote 50+ knowledge base articles in Jira and Confluence, which cut resolution time on repeat tickets.
  • Coordinated cross-functional incident response through Jira, which cut response times by 15%.

Information Technology Security Analyst

Intact Public Entities | Cambridge, ON | June 2022 to February 2025

  • Rewrote the security policies into something people could follow. Unauthorized access dropped 75% and we saved about $20K a year in breach costs.
  • Engineered patch management scripts that cut patching time by 90% and hardened the endpoints they touched.
  • Ran 200+ vulnerability tests through Qualys VMDR, lowering risk exposure by 30% and remediation times by 40%.
  • Built the security training programme. Compliance went up 25% and phishing incidents fell by half.
  • Investigated and resolved security incidents in Microsoft Sentinel, consistently meeting SLA targets.
  • Ran quarterly audits of privileged access, special permissions, and control groups to enforce least privilege.

Technical Support Analyst L2

Cineplex Digital Media | Waterloo, ON | April 2021 to June 2022

  • Monitored the health of Linux-based digital signage networks and worked customer issues through to resolution against SLA.
  • Ran remote diagnostics and repairs over SSH and VNC.
  • Built API integrations and scripts to automate the delivery process.
  • Validated each deployment before handing it to the Day 2 customer success team, so nothing arrived broken.
  • Managed dispatch of technicians, spare parts and equipment to sites.

Flow Operations Clerk

Loblaw Companies Limited | Kitchener, ON | July 2019 to November 2020

Worked here while completing my post-graduate diploma at Conestoga College.

Web Developer

B-GHUD Academy of Information Technology | Mavelikkara, Kerala, India | July 2017 to March 2019

  • Built and maintained the institution's website and web applications in JavaScript, PHP, and SQL.
  • Owned the security and privacy of the institution's site and data.
  • Managed the content management system and other web tooling.
  • Provided technical support and training to faculty and staff.

Selected work

Four things I've done that I can talk about in detail. Anything specific to my employer's environment or detection logic stays off this page, so if you want the methodology, ask me and I'll walk you through it.

hunting, not just alerting

Hunting with breach and attack simulation

I run monthly Cymulate simulations across network and endpoint to find the gaps our alerting doesn't cover. The point is to test controls against realistic attack behaviour before someone tests them for real, rather than waiting for the queue to tell us we missed something.

Surfaced and closed 25% more control gaps than alert-driven review alone.

Control gaps surfaced +25%

Cutting false positives without losing signal

I tune Microsoft Sentinel detection rules with one goal: fewer alerts nobody acts on, and better coverage where it counts. Reducing noise is only useful if the detections that matter keep firing.

30% reduction in false positive alert volume, with higher fidelity on critical attack vectors.

False positive volume -30%

Security policies and training people actually followed

Policy documents are easy to write and easy to ignore. I rewrote ours around what people could realistically do, then built the training that went with it and ran 200+ vulnerability tests to check whether any of it was working.

Unauthorized access down 75%, about $20K a year saved in breach costs, compliance up 25%, phishing incidents halved.

Unauthorized access -75%
Security compliance +25%
Phishing incidents -50%

Patch automation that gave the team its week back

Patching was slow, manual, and inconsistent. I wrote scripts to handle the repeatable parts and left humans to make the judgement calls. Remediation times dropped by 40% and risk exposure by 30%.

Patching time down 90%, remediation time down 40%.

Patching time -90%
Remediation time -40%

Certifications and education

Certifications

  • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
  • CompTIA CySA+ ce (CS0-003)
  • Microsoft Certified: Azure Administrator Associate (AZ-104)
  • Qualys Vulnerability Detection and Response (VMDR)
  • Qualys Patch Management
  • Qualys CyberSecurity Asset Management (CSAM)

Credential IDs available on request.

Education

  • Post Graduate, Enterprise Content Management | Conestoga College, Kitchener, ON | 2019 to 2020
  • B.Tech, Computer Science | University of Kerala, Kerala, India | August 2012 to March 2016

Contact

If you're hiring for a SOC or security operations role, or you just want to argue about detection tuning, my inbox is open. LinkedIn is the fastest way to reach me.

LinkedIn | | Resume (PDF)

Private details (password required)

Phone number and certification credential IDs, encrypted with AES-256-GCM and a 600,000-round PBKDF2 key. The password is not stored anywhere on this site. If you need these details and do not have it, message me on LinkedIn and I will send them.