Hi, I'm Shivam.
Junior IT Administrator with 2 years of experience in Microsoft 365, Entra ID, and Windows systems — growing into security operations through Security+ study and hands-on SOC lab work.
I work at the intersection of identity and access management and hands-on security operations — administering Active Directory and Microsoft Entra ID, and building home-lab environments that simulate real SOC workflows, from log ingestion to threat detection. Every lab is a step toward operating at the level a production security team expects.
Learn MoreJunior IT Administrator with 2 years of experience supporting Microsoft 365, Entra ID, Windows systems, and network troubleshooting. Developing strong security foundations through Security+ studies and hands-on SOC lab work focused on alert triage, log analysis, and threat identification — skilled in onboarding, device configuration, VPN support, and monitoring system activity for anomalies, with a track record of fast, accurate problem solving and clear documentation.
- Assisted in containment and triage during a ransomware incident by isolating compromised systems, analyzing event logs (4624/Type 3), and identifying lateral-movement patterns against the client's Windows domain.
- Monitored system, application, and security logs across Microsoft 365 and endpoint environments to identify anomalies, investigate issues early, and escalate potential security events.
- Investigated suspicious sign-ins, MFA failures, email anomalies, and access-related incidents, determining root cause and documenting findings for escalation.
- Responded to user-reported incidents through the ticketing system, performing initial triage, gathering evidence, and following incident handling procedures.
- Reviewed Microsoft Defender alerts and performed basic remediation to keep devices compliant and up to date.
- Supported Microsoft 365 and Entra ID operations including group assignments, access troubleshooting, conditional access checks, and mailbox configuration.
- Followed runbooks for secure provisioning and deprovisioning while maintaining identity hygiene and reducing access-related incidents.
- Troubleshot DNS/DHCP conflicts, VPN failures, IP conflicts, and firewall access requests, restoring secure connectivity under time-sensitive conditions.
- Executed documented procedures during three Microsoft 365 migrations (~100 users each), validating security configurations and resolving post-migration issues quickly.
Home SOC Lab
OngoingBuilding a full security operations lab from the ground up to get hands-on experience with SIEM, XDR, IDS, and endpoint telemetry. Currently deploying Elastic SIEM and Wazuh, configuring Windows endpoints with Sysmon for telemetry collection, and beginning to analyze authentication and process-creation events. Each phase — configurations, detections, and investigation notes — is documented as it's built, mapping observed behaviors to MITRE ATT&CK techniques along the way.
Let's talk identity, access, or security operations.