J. METHMAL

Experience

A career built inside live security operations

From a security operations internship in Sri Lanka to remote incident response for a US-based MSSP — every role has added a new layer of operational depth across banking, healthcare, and pharmaceutical clients.

Incident Response Analyst

Armature Systems

Apr 2026 — Present

Remote · USA-based MSSP

Current

Working remotely with a US-based Managed Security Services Provider, investigating and responding to security incidents and supporting alert tuning across pharmaceutical, biopharmaceutical, healthcare, and enterprise client environments.

  • Provide security operations and monitoring support across multiple client environments, covering endpoint, identity, email, and network security telemetry.
  • Investigate, triage, and respond to security incidents — reducing false positives and driving alerts to resolution within client SLAs.
  • Review alerts across SentinelOne, CrowdStrike Falcon, Cortex XDR, Microsoft Defender, and Microsoft Sentinel, recommending tuning and exclusions to cut down noise.
  • Currently building out a structured process for alert-exclusion review and Tines automation workflow creation to streamline triage and response across client SOCs.
  • Support identity, email, and network security investigations across Okta, Abnormal Security, Zscaler, and Google Workspace.
  • Manage operational workflows and incident tracking in Jira for client environments.
  • Partner directly with clients in highly regulated industries to recommend security process improvements and operational efficiencies.
Incident ResponseDetection EngineeringSecurity AutomationIdentity & Access SecurityMSSP Operations
SentinelOneCrowdStrike FalconCortex XDRMicrosoft DefenderMicrosoft SentinelOktaAbnormal SecurityZscalerGoogle Workspace SecurityTines

Engineer – IT Security

Commercial Bank of Ceylon PLC

Aug 2025 — Apr 2026

Sri Lanka · On-site

Operated at the core of the bank's security operations, owning detection engineering inside Cortex XSIAM and leading incident response across critical banking infrastructure.

  • Monitored and managed Cortex XSIAM by onboarding log sources, creating fine-tuned detection rules, automating defenses, and conducting threat hunting to ensure timely remediation.
  • Collaborated with Mandiant on a Compromise Assessment, deploying forensic artifact collection agents across 9,000+ devices including servers, endpoints, ATMs, and CRMs.
  • Triaged and responded to incidents, ensuring timely containment and remediation across the bank's infrastructure.
  • Collaborated with cross-functional teams to mitigate risks, document incidents and lessons learned, and strengthen the organization's security posture.
Detection EngineeringIncident ResponseCompromise AssessmentThreat Hunting
Cortex XSIAMMandiant Forensic ToolingMITRE ATT&CK

Associate Analyst – Managed Security Services

MillenniumIT ESP

Sep 2024 — Aug 2025

Sri Lanka · On-site

Worked inside a 24/7 SOC defending multiple client environments, while leading security operations for a flagship healthcare and consumer conglomerate client.

  • Executed incident response in a 24/7 SOC to safeguard organizational information security, adhering to client SLAs.
  • Collaborated with Security Operations and support teams to monitor, triage, and escalate security alerts across on-premises, AWS, and Azure environments.
  • Maintained incident records and produced detailed client reports, ensuring critical data availability for uninterrupted operations.
  • Enhanced detection accuracy by collaborating on use case development and SIEM/EDR optimizations.
  • Served as Project Lead for a flagship client within a consumer and healthcare-focused conglomerate.
Incident ResponseThreat IntelligenceCloud SecurityMalware DetectionVulnerability Mgmt
FortiSIEMCrowdStrike EDRAlienVault USM AnywhereThe HiveMicrosoft SentinelNetScout ArborSentinelOne EDRMicrosoft Defender XDRIBM QRadar

Intern – Managed Security Services

MillenniumIT ESP

May 2024 — Oct 2024

Sri Lanka · On-site

Entry point into managed security services — building the fundamentals of SOC monitoring, vulnerability management, and security reporting.

  • Supported the SOC with incident monitoring, threat and vulnerability management, and daily security reporting.
  • Analyzed and responded to security incidents, honing skills in incident response and threat intelligence.
Incident ManagementReporting & Documentation

Intern – Managed Security Services

eBuilder Security

Jul 2023 — Oct 2023

Sri Lanka · On-site

First exposure to professional security operations — spanning project management, incident handling, AWS administration, and offensive security awareness work.

  • Conducted cybersecurity project management (Basecamp), handled incidents (Jira, TOPdesk), administered AWS, and performed social engineering (OSINT) and phishing simulations.
  • Delivered security awareness training and supported AWS administration for secure infrastructure management.
Project ManagementSocial EngineeringSecurity Awareness

Open to security research collaborations & freelance engineering work

Let's strengthen your security posture — or build something new.

Whether it's detection engineering, a compromise assessment, or a full-stack build — I'm always glad to talk shop.